Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

‘Girls Like Girls’ favors nostalgia over the depth of a young queer awakening story

This special Babbel offer gives you lifetime access to lessons created by linguists

Deadmau5 adopts a cat he rescued by donating to an animal shelter

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » New critical SAP NetWeaver flaws have been exploited by the drop web shell, the Blue Tratel framework
Celebrities

New critical SAP NetWeaver flaws have been exploited by the drop web shell, the Blue Tratel framework

By April 25, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

April 25, 2025Ravi LakshmananVulnerability/Enterprise Security

Threat actors may be uploading JSP Web shells with the aim of exploiting new vulnerabilities in SAP NetWeaver to facilitate uploading malicious files and code execution.

“Exploitation is likely linked to either a previously disclosed vulnerability, such as CVE-2017-9844, or an unreported remote file inclusion (RFI) issue,” ReliaQuest said in a report published this week.

Cybersecurity said there is a possibility of zero-day stems from the fact that some of the affected systems are already running the latest patches.

Cybersecurity

The flaw is evaluated as rooted in the “/DevelopmentServer/Metadatauploader” endpoint in the NetWeaver environment, allowing unknown threat actors to upload malicious JSP-based web shells to “Servlet_jsp/IRJ/root/”, providing a path for permanent remote access and an additional payload.

Put another way, a lightweight JSP web shell is configured to upload malformed files, entrench infected hosts, execute remote code, and run Siphon-sensitive data.

Selected incidents have been observed using a framework after Brute Ratel C4 extraction and a well-known technique called Heaven’s Gate, which bypasses endpoint protection.

In at least one case, threat actors took several days from successful initial access to subsequent exploitation, increasing the likelihood that attackers are early access brokers (IABs) gaining and selling access to other threat groups at underground forums.

“Our research reveals troubling patterns and suggests that enemies are leveraging known exploits and combining them with a combination of techniques that evolve to maximize their impact,” says ReaQuest.

“SAP solutions are often used by government agencies and businesses and are highly valuable targets for attackers. As SAP solutions are often deployed on-premises, the security measures for these systems are left to the user. Updates and patches that are not applied quickly can put these systems at greater risk.”

Coincidentally, SAP has released an update to address the biggest severity security flaw (CVE-2025-31324, CVSS score: 10.0).

Cybersecurity

“SAP NetWeaver Visual Composer Metadata uploaders are not protected with proper authorization, allowing unguaranteed agents to upload viable binaries that can cause serious harm to the host system.”

CVE-2025-31324 could refer to the same unreported security flaw, given that the former also affects the metadata uploader component.

This disclosure comes just over a month after the US Cybersecurity and Infrastructure Security Agency (CISA) warned of the aggressive exploitation of another highly empirical NetWeber flaw (CVE-2017-12637) that allows attackers to retrieve sensitive SAP configuration files.

update

ReliaQuest has confirmed with Hacker News that the malicious activity mentioned above is actually leveraging a new security vulnerability that is being tracked as CVE-2025-31324.

“The vulnerability identified during an investigation published on April 22, 2025 was initially suspected to be a remote file inclusion (RFI) issue,” the company said. “However, SAP later identified it as an unlimited file upload vulnerability, allowing attackers to upload malicious files directly to the system without permission.”

(The story was updated after publication to confirm the exploitation of the new zero-day flaws.)

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleWhy NHIS is the most dangerous blind spot in security
Next Article Top 5 Agency Stories of the Week

Related Posts

Katie Holmes evokes ‘office siren’ at Max Mara Resort 2027 show

June 16, 2026

Duchess Kate wears Patrick McDowell bespoke with Order of the Garter

June 15, 2026

Melania Trump shows off her high fashion look in Dolce & Gabbana at UFC 250

June 15, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

‘Girls Like Girls’ favors nostalgia over the depth of a young queer awakening story

This special Babbel offer gives you lifetime access to lessons created by linguists

Deadmau5 adopts a cat he rescued by donating to an animal shelter

Ranking of all official World Cup songs

Trending Posts

Deadmau5 adopts a cat he rescued by donating to an animal shelter

June 16, 2026

Ranking of all official World Cup songs

June 16, 2026

Jennifer Lopez needed to find herself again after divorce from Affleck

June 16, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.