References https://www.ihonker.com/thread-33342-1-1.html https://cloud.tencent.com/developer/article/2549764 https://x.threatbook.com/v5/article?threatInfoID=157415 https://www.ithome.com.tw/news/170728 https://nvd.nist.gov/vuln/detail/CVE-2025-31324 https://onapsis.com/blog/how-to-remediate-sap-zero-day-cve-2025-31324/ https://zeropath.com/blog/sap-netweaver-cve-2025-42944 https://nvd.nist.gov/vuln/detail/CVE-2025-42944 https://thehackernews.com/2025/10/new-sap-netweaver-bug-lets-attackers.html https://redrays.io/blog/cve-2025-42944-critical-severity-remote-code-execution-in-sap-netweaver-rmi-p4/
Related VulnerabilitiesPoCCVE-2016-2389: SAP xMII 15.0 for SAP NetWeaver 7.4 - Local File InclusionPoCCVE-2017-12637: SAP NetWeaver Application Server Java 7.5 - Local File InclusionPoCCVE-2020-6287: SAP NetWeaver AS JAVA 7.30-7.50 - Remote Admin AdditionPoCCVE-2021-33690: SAP NetWeaver Development Infrastructure - Server Side Request ForgeryPoCCVE-2025-31324: SAP NetWeaver Visual Composer Metadata Uploader - DeserializationPoCsap-netweaver-backdoor: SAP NetWeaver - Backdoor DetectionPoCsap-netweaver-portal: SAP NetWeaver Portal - DetectPoCsap-nw-webgui: SAP NetWeaver WebGUI DetectionSAP Netweaver metadatauploader 远程代码执行漏洞SAP Netweaver publicinfo CVE-2022-22536请求走私漏洞SAP NetWeaver AS JAVA 7.30-7.50 管理员用户添加(CVE-2020-6287)SAP NetWeaver应用服务器Java 7.5 -本地文件包含(CVE-2017-12637)SAP NetWeaver AS Java任意用户注册漏洞(CVE-2020-6287)