
CVE-2025-31324 & CVE-2025-42999 vulnerability and compromise assessment tool
Onapsis and Mandiant have collaborated to release an open-source tool to assist SAP customers in identifying potential compromise related to CVE-2025-31324 and CVE-2025-42999, a critical 0-day vulnerability in SAP NetWeaver Java systems.
This tool is intended for local, white-box execution by system administrators with access to potentially affected environments. It supports vulnerability assessment, simple compromise assessment and artifact collection.
This tool currently supports the following functionality:
LICENSE INFORMATION: This tool is released under the Apache 2.0 open source license. Please see bundled license information.
DISCLAIMER: This tool was developed to support urgent investigation and response efforts related to the active exploitation of CVE-2025-31324 and CVE-2025-42999. As of June 6, 2025, this tool is no longer under active development or monitoring. It remains available for future debugging and reference purposes; however, it will not receive further updates, enhancements, or ongoing support. Users should evaluate its applicability based on their current needs and use it at their own discretion.
This tool automates checking of vulnerability and IOC information running in live OS with the permissions of the user executing the script. This is NOT a substitute for forensic analysis or advanced incident response. Sophisticated attackers often clean up evidence of their intrusion while deploying rootkits and leveraging techniques to evade detection.
This tool is provided as-is, without warranty or liability. Use at your own risk.
The scripts are developed in Python 3 and require you to install the following dependencies:
python3 -m venv .venv
. .venv/bin/activate
pip install -r requirements.txt
Once you install the dependencies, you can use Python to run the scripts and get Help from the command line.
# Syntax: python3 <tool_name>.py <path> [--single] [--offline]
Scan Parameters:
<path> --- Refers to the root directory of the SAP application file system you want to scan. This should be the base of the SAP system, either from a mounted backup or a live environment.--single --- Run a scan for a individual SID/Instance directory (not root or base SAP directory with multiple systems or instances)--offline --- Run without internet connection (no check for upgrades against GitHub API)For a full list of command line options and flags use --help parameter.
[!IMPORTANT] This tool scan for files under the JAVA server file system as specified in SAP Security Note 3593336:
C:\usr\sap\<SID>\<InstanceID>\j2ee\cluster\apps\sap.com\irj\servlet_jsp\irj\rootC:\usr\sap\<SID>\<InstanceID>\j2ee\cluster\apps\sap.com\irj\servlet_jsp\irj\workC:\usr\sap\<SID>\<InstanceID>\j2ee\cluster\apps\sap.com\irj\servlet_jsp\irj\work\syncIf the path given is a root live file-system (for example
/orC:\), the tool will expect/usr/sapstandard SAP installation directory. Then the tool will scan all<SID>/<INSTANCE>/sub-directories by default (using wildcards).If doing a partial scan, use
--singleand specify the full path to the instance folder that contains thej2eeSAP Java directory.
[!CAUTION] This design is intended to scan all possible suspicious files in all SID / Instances, while avoiding incorrect detection of familiar files. Any file outside this standard folder structure will not be detected, and an error will be raised if
j2eesub-directory is not found.The component manifest is also expected to be in
j2ee/cluster/apps/sap.com/devserver_metadataupload_ear/standard sub-directory. If not found, it will not be analyzed against vulnerable un-patched versions.Expected Log path is
j2ee/cluster/<SERVER>/log/system/httpaccess/, with files namedresponsesandtrcextension for SAP propietary log format.-clfsuffix is expected for Common Log Format files. If not found, an error/warning message will be raised.
Mounted filesystem at /mnt/sapserver (component vulnerable, single instance scan for SID J00):
python3 onapsis-mandiant-CVE-2025-31324-vuln-compromise-assessment.py /mnt/sapserver/usr/sap/SID/J00 --single