Technology NewsTechnology NewsTechnology News
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Reading: Hackers Actively Exploiting SAP NetWeaver Zero-Day Vulnerability
Share
Font ResizerAa
Technology NewsTechnology News
Font ResizerAa
Search
  • Computing
  • AI
  • Robotics
  • Cybersecurity
  • Electric Vehicle
  • Wearables
  • Gaming
  • Space
Follow US
  • Cookie Policy (EU)
  • Contact
  • About
© 2025 NEWSLINKER - Powered by LK SOFTWARE
Cybersecurity

Hackers Actively Exploiting SAP NetWeaver Zero-Day Vulnerability

Highlights

  • Widespread exploitation of SAP NetWeaver vulnerability CVE-2025-31324 observed.

  • An emergency patch is available to SAP customers to address the flaw.

  • Experts advise immediate patching to prevent full system compromises.

Ethan Moreno
Last updated: 25 April, 2025 - 9:10 pm 9:10 pm
Ethan Moreno 4 weeks ago
Share
SHARE

A critical flaw in SAP NetWeaver’s Visual Composer component has been widely exploited by threat actors, putting numerous organizations at risk. This zero-day vulnerability, identified as CVE-2025-31324, allows unauthorized file uploads, potentially compromising entire systems. Experts warn that the vulnerability could have far-reaching impacts across various industries globally.

Contents
Vulnerability DetailsActive Exploitation and ImpactMitigation Efforts

The extent of this breach surpasses previous incidents involving SAP systems, marking it as one of the most severe vulnerabilities exploited in recent times. Earlier SAP vulnerabilities had limited exploitation, but CVE-2025-31324 has seen rapid and widespread attacks, emphasizing the urgent need for security measures.

Vulnerability Details

The CVE-2025-31324 flaw affects the SAP Visual Composer component of SAP NetWeaver, a platform integral to many enterprise applications. This defect permits unauthorized users to upload files, granting them the ability to execute code remotely and fully compromise the system. Onapsis estimates approximately 10,000 SAP instances might be vulnerable based on internet server searches.

Active Exploitation and Impact

“This isn’t a theoretical threat — it’s happening right now,”

stated Benjamin Harris, CEO of watchTowr. Additionally,

“SAP solutions are often used by government agencies and enterprises, making them high-value targets for attackers,”

as noted by ReliaQuest researchers. The vulnerability has been actively exploited, with attackers deploying web shell backdoors to secure further access to compromised systems. WatchTowr has observed a significant spike in attempts and breaches across critical industries, affecting an estimated 50-70% of internet-facing SAP NetWeaver systems.

Mitigation Efforts

SAP has released an emergency patch to address the vulnerability, available exclusively to customers with login credentials to their support portal. Researchers and incident responders urge all SAP NetWeaver users to apply the patch immediately to prevent unauthorized access and system compromise. Due to the high value of SAP solutions in government and enterprise sectors, the vulnerability poses a substantial risk if not promptly addressed.

The emergence of CVE-2025-31324 underscores the persistent vulnerabilities within widely used enterprise systems like SAP NetWeaver. Organizations must remain vigilant and prioritize the implementation of security patches to safeguard their infrastructure effectively. Continuous monitoring and swift response strategies are essential to mitigate the risks posed by such critical exploits in the future.

You can follow us on Youtube, Telegram, Facebook, Linkedin, Twitter ( X ), Mastodon and Bluesky

You Might Also Like

Massachusetts Student Admits Guilt in Massive School Data Breach

Telecom Breach Leaves Executives Stunned as Government Faces Backlash

House Bill Proposes Overhaul for Federal Cyber Workforce Training

CIOs Tackle Quantum Threat in Encryption Race

FTC Seeks New Tools to Combat Deepfake Pornography

Share This Article
Facebook Twitter Copy Link Print
Ethan Moreno
By Ethan Moreno
Ethan Moreno, a 35-year-old California resident, is a media graduate. Recognized for his extensive media knowledge and sharp editing skills, Ethan is a passionate professional dedicated to improving the accuracy and quality of news. Specializing in digital media, Moreno keeps abreast of technology, science and new media trends to shape content strategies.
Previous Article Mary Moriarty Criticized for Not Charging Tesla Vandal
Next Article GAM Enterprises Presents Warehouse Automation Trends at Robotics Summit

Stay Connected

6.2kLike
8kFollow
2.3kSubscribe
1.7kFollow

Latest News

Sam Altman Backs Retro Biosciences for Life-Extending Therapies
Technology
TRON1 Robot Expands Capabilities with New Features
Robotics
Simbe Robots Boost Retail Efficiency with AI Innovations
Robotics
Tesla Prepares Massive Robotaxi Rollout in Austin
Electric Vehicle
Orbit 5.0 Powers Up Boston Dynamics’ Spot Robots
Robotics
NEWSLINKER – your premier source for the latest updates in ai, robotics, electric vehicle, gaming, and technology. We are dedicated to bringing you the most accurate, timely, and engaging content from across these dynamic industries. Join us on our journey of discovery and stay informed in this ever-evolving digital age.

ARTIFICAL INTELLIGENCE

  • Can Artificial Intelligence Achieve Consciousness?
  • What is Artificial Intelligence (AI)?
  • How does Artificial Intelligence Work?
  • Will AI Take Over the World?
  • What Is OpenAI?
  • What is Artifical General Intelligence?

ELECTRIC VEHICLE

  • What is Electric Vehicle in Simple Words?
  • How do Electric Cars Work?
  • What is the Advantage and Disadvantage of Electric Cars?
  • Is Electric Car the Future?

RESEARCH

  • Robotics Market Research & Report
  • Everything you need to know about IoT
  • What Is Wearable Technology?
  • What is FANUC Robotics?
  • What is Anthropic AI?
Technology NewsTechnology News
Follow US
About Us   -  Cookie Policy   -   Contact

© 2025 NEWSLINKER. Powered by LK SOFTWARE
Welcome Back!

Sign in to your account

Register Lost your password?