CVE-2025-31324 Scanner
Targets the deserialization endpoint in SAP NetWeaver, allowing attackers to execute arbitrary code remotely without authentication.
Short Info
Level
Single Scan
Single Scan
Can be used by
Asset Owner
Estimated Time
10 seconds
Time Interval
1 month 20 days
Scan only one
Domain, Subdomain, IPv4
Toolbox
SAP NetWeaver is a comprehensive software platform used by large enterprises to integrate business processes across diverse systems. It serves as a foundation for many SAP applications, enabling seamless data exchange and workflow automation in sectors like finance, logistics, and HR. Organizations rely on it to streamline operations and support complex digital transformations.
CVE-2025-31324 is a critical deserialization of untrusted data vulnerability. It arises when the platform deserializes user-supplied data without proper validation, allowing attackers to inject malicious objects. This flaw stems from insecure handling of serialized Java objects in the application server.
The vulnerability specifically targets the /sap/bc/soap/rfc endpoint, where SOAP messages are processed. Attackers can craft a malicious serialized Java object within the request payload, exploiting the deserialization process to execute arbitrary code on the server. No authentication is required for exploitation.
If exploited, an attacker gains full remote code execution with system-level privileges, leading to complete compromise of the SAP NetWeaver server. This can result in data theft, service disruption, and lateral movement within the corporate network. The CVSS score of 10.0 underscores the maximum severity of this vulnerability.