- SAP revealed a 10/10 error in Netweaver Visual Composer
- The error allows threat actors to upload malware
- Researchers claim up to 1,200 cases are vulnerable
More than 1,200 SAP deposits risk being hijacked, researchers say as a critical vulnerability was found abused in nature. Earlier this week, SAP said it found an unauthorized file upload vulnerability in Netweaver Visual Composers Metadata Uploader component.
Visual Composer is a development tool that allows users to build web -based business applications without writing code. It is mostly used to create dashboards, forms and interactive reports. On the other hand, the metadata -Uploader is a tool to import external data models (metadata) into the visual composer design environment. This allows developers to connect to external data sources (web services, databases or SAP systems).
The vulnerability found is now tracked as CVE-2025-31324. It carries the maximum severity (10/10) and stems from the fact that the uploader is not protected with proper permission, allowing unauthorized actors to upload malicious executable.
Fortune 500 in danger
When it discovered the error, SAP first released a solution, and then at the end of April, a patch.
Now, users are advised to use it as soon as possible as more cyber security companies confirmed that the error is abused in nature. According to Bleeping computer, Reliaquest, Watchtowr and Onapsis are just some of the companies that observed that the error was exploited in attacks where threat players dropped web shells on vulnerable servers.
However, SAP told Bleeping computer that it is not aware of any attack that affected customer data or systems.
The jury is still out of how many organizations are actually vulnerable. While the Shadows Server Foundation claims 427 servers are exposed to the Internet, Onyphe says there are 1,284 cases, of which 474 are already compromised.
“Something like 20 Fortune 500/Global 500 companies are vulnerable and many of them are compromised,” Onyphe CTO Patrice Auffret told Bleeping computer.
Via Bleeping computer