Netskope Threat Labs

SERVER-WEBAPP SAP NetWeaver Visual Composer arbitrary Java .class file upload attempt

IPS-NPA

1 SID: 64829

Detects an attempt to exploit CVE-2025-31324, an arbitrary file upload flaw that can plant webshells on the server in SAP NetWeaver Visual Composer arbitrary Java .class. The flaw saw mass exploitation of internet-facing SAP NetWeaver servers to upload webshells.