CVE-2025-31324 Scanner

Targets the deserialization endpoint in SAP NetWeaver, allowing attackers to execute arbitrary code remotely without authentication.

Short Info


Level

Critical

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

10 seconds

Time Interval

1 month 20 days

Scan only one

Domain, Subdomain, IPv4

Toolbox

SAP NetWeaver is a comprehensive software platform used by large enterprises to integrate business processes across diverse systems. It serves as a foundation for many SAP applications, enabling seamless data exchange and workflow automation in sectors like finance, logistics, and HR. Organizations rely on it to streamline operations and support complex digital transformations.

CVE-2025-31324 is a critical deserialization of untrusted data vulnerability. It arises when the platform deserializes user-supplied data without proper validation, allowing attackers to inject malicious objects. This flaw stems from insecure handling of serialized Java objects in the application server.

The vulnerability specifically targets the /sap/bc/soap/rfc endpoint, where SOAP messages are processed. Attackers can craft a malicious serialized Java object within the request payload, exploiting the deserialization process to execute arbitrary code on the server. No authentication is required for exploitation.

If exploited, an attacker gains full remote code execution with system-level privileges, leading to complete compromise of the SAP NetWeaver server. This can result in data theft, service disruption, and lateral movement within the corporate network. The CVSS score of 10.0 underscores the maximum severity of this vulnerability.

Get started to protecting your digital assets