Summary : SAP has released critical security updates for its May 2025 patch, including fixes for two actively exploited zero-day vulnerabilities in SAP NetWeaver Visual Composer.
SAP Visual Composer is not installed by default, however it is enabled because it was a core component used by business process specialists to develop business application components without coding.
OEM | SAP |
Severity | Critical |
Date of Announcement | 2025-05-13 |
No. of Vulnerabilities Patched | 16 |
Actively Exploited | Yes |
Exploited in Wild | Yes |
Advisory Version | 1.0 |
Overview
The most severe issue, CVE-2025-31324 (CVSS 10.0), is a critical unauthenticated file upload vulnerability that has been exploited in the wild since January 2025 for remote code execution (RCE).
This issue was originally addressed in an SAP security note issued on April 24, 2025, and has since been supplemented by a second vulnerability, CVE-2025-42999, involving insecure deserialization.
These vulnerabilities have been used together in chained attacks to gain full system access on vulnerable SAP NetWeaver servers.
Vulnerability Name | CVE ID | Product Affected | Severity | CVSS Score |
Unauthenticated File Upload (RCE) | CVE-2025-31324 | SAP NetWeaver | Critical | 10.0 |
Insecure Deserialization (RCE) | CVE-2025-42999 | SAP NetWeaver | Critical | 9.1 |
Technical Summary
Attackers have leveraged two flaws in SAP NetWeaver Visual Composer in chained exploit scenarios to gain unauthorized remote access and execute arbitrary commands.
CVE-2025-31324 enables unauthenticated file uploads, and CVE-2025-42999 allows privileged users to exploit insecure data deserialization for command execution.
These vulnerabilities have impacted hundreds of internet-facing SAP instances, including systems operated by major enterprises.
CVE ID | System Affected | Vulnerability Details | Impact |
CVE-2025-31324 | SAP NetWeaver Visual Composer | Unauthenticated file upload vulnerability in development server. | Remote Code Execution (RCE) without privileges |
CVE-2025-42999 | SAP NetWeaver Visual Composer | Insecure deserialization in Visual Composer user-accessible function. | Remote Code Execution (RCE) without privileges |
Source: SAP
In addition to the actively exploited vulnerabilities, several other High Severity Vulnerabilities were also addressed:
Remediation:
General Recommendations:
Conclusion:
References:
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Ut elit tellus, luctus nec ullamcorper mattis, pulvinar dapibus leo.