HomeSecuritySAP NetWeaver: Public Exploit for chained vulnerabilities

SAP NetWeaver: Public Exploit for chained vulnerabilities

A new exploit that combines two critical (now patched) vulnerabilities in SAP NetWeaver has emerged, putting organizations and users at risk.

SAP NetWeaver exploit vulnerabilities

The exploit combines CVE-2025-31324 and CVE-2025-42999 to bypass authentication and achieve remote code execution, according to security firm Onapsis.

CVE-2025-31324 (CVSS score: 10.0) is related to the absence of authentication in the SAP NetWeaver Visual Composer development server, while CVE-2025-42999 (CVSS score: 9.1) is related to insecure Deserialization on the same server.

See also: CISA: Warns of vulnerability in Trend Micro Apex One

SAP NetWeaver: Vulnerability Fix

These vulnerabilities were patched by SAP in April and May 2025, but not before they were used by malicious actors as zero-days. The first attacks were recorded in March. Several ransomware and extortion groups, including Qilin, BianLian, and RansomExx , have been observed exploiting these vulnerabilities, along with several China-linked espionage groups targeting critical infrastructure networks

The existence of the exploit was first reported by vx-underground, who noted that it was released by the Scattered Lapsus$ Hunters, a new alliance formed by Scattered Spider and ShinyHunters.

Onapsis, for its part, stated: “These vulnerabilities allow an unauthorized attacker to execute arbitrary commands on the target SAP System, including uploading arbitrary files. This can lead to remote code execution (RCE) and complete compromise of the affected system and SAP business data and processes.”

See also: Intel vulnerabilities allowed employee data breach

SAP NetWeaver: Public Exploit for chained vulnerabilities

The exploit can be used to deploy web shells, as well as perform living-off-the-land (LotL) attacks by executing operating system commands without leaving any additional files on the compromised system. These commands are executed with SAP administrator privileges , providing unauthorized access to SAP system data and resources.

The attack chain first uses the CVE-2025-31324 vulnerability to bypass authentication and upload the malicious payload to the server. The Deserialization vulnerability (CVE-2025-42999) is then used to decompress the payload and execute it with elevated privileges.

Onapsis warned that the publication of this deserialization gadget is concerning because it can be reused in other contexts, such as exploiting deserialization vulnerabilities patched by SAP in July [(CVE-2025-30012 (CVSS score: 10.0), CVE-2025-42963 (CVSS score: 9.1), CVE-2025-42964 (CVSS score: 9.1), CVE-2025-42966 (CVSS score: 9.1), CVE-2025-42980 (CVSS score: 9.1)].

See also: PyPI: Malicious packages exploit dependency for supply chain attacks

Describing the malicious actors as having extensive knowledge of SAP applications, Onapsis urges SAP users to apply the latest patches as soon as possible, review and restrict access to SAP applications from the internet, and monitor SAP applications for any signs of compromise.

SAP NetWeaver: Public Exploit for chained vulnerabilities

The new SAP NetWeaver exploit once again highlights how attractive high-value enterprise systems for malicious actors. The fact that the exploit combines two critical vulnerabilities (CVE-2025-31324 and CVE-2025-42999) to achieve authentication bypass and remote code executionmakes the threat extremely dangerous.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Critical PostgreSQL vulnerabilities allow Code Injection

Furthermore, the incident highlights the classic problem of patch management in large enterprise systems: even if patches are made available by the vendor, many systems remain exposed due to delays in applying updates or due to operational limitations (e.g. downtime in critical environments).

SAP NetWeaver is a cornerstonefor critical business functions (ERP, finance, procurement, HR). A breach is not just a technical loss, but can affect supply chains, financial transactions and confidential data. The involvement of ransomware groups (Qilin, BianLian, RansomExx) and state-sponsored APTs shows that the threat is twofold: financial extortion and espionage of critical infrastructure.


📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS