critical·Product Based Web Vulnerabilities·Updated Apr 26, 2025

CVE-2025-31324 Scanner

Targets the deserialization endpoint in SAP NetWeaver, allowing attackers to execute arbitrary code remotely without authentication.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.3k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2025-31324
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
SAP NetWeaver (Visual Composer development server)by SAP_SE
VCFRAMEWORK 7.50
Updated Aug 22, 2026View on NVD →
Detail

SAP NetWeaver is a comprehensive software platform used by large enterprises to integrate business processes across diverse systems. It serves as a foundation for many SAP applications, enabling seamless data exchange and workflow automation in sectors like finance, logistics, and HR. Organizations rely on it to streamline operations and support complex digital transformations.

CVE-2025-31324 is a critical deserialization of untrusted data vulnerability. It arises when the platform deserializes user-supplied data without proper validation, allowing attackers to inject malicious objects. This flaw stems from insecure handling of serialized Java objects in the application server.

The vulnerability specifically targets the /sap/bc/soap/rfc endpoint, where SOAP messages are processed. Attackers can craft a malicious serialized Java object within the request payload, exploiting the deserialization process to execute arbitrary code on the server. No authentication is required for exploitation.

If exploited, an attacker gains full remote code execution with system-level privileges, leading to complete compromise of the SAP NetWeaver server. This can result in data theft, service disruption, and lateral movement within the corporate network. The CVSS score of 10.0 underscores the maximum severity of this vulnerability.

Solution Advice
  • Apply the latest SAP security patch for CVE-2025-31324 immediately.
  • Disable unnecessary deserialization endpoints in SAP NetWeaver.
  • Implement strict input validation and sanitization for all SOAP messages.
  • Use a Web Application Firewall (WAF) to filter malicious serialized objects.
  • Restrict network access to the /sap/bc/soap/rfc endpoint to trusted IPs only.
  • Enable SAP Security Notes and conduct regular vulnerability scans.
  • Monitor logs for unusual deserialization attempts or unexpected Java exceptions.
  • Segment the SAP NetWeaver server from other critical systems to limit blast radius.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

SAP NetWeaver Deserialization Scanner | S4E Free Check S4E