All CVEs View on NVD
CVE-2025-31324
CRITICAL10.0
CISA KEV
Published 2025-04-24 · Updated 2026-08-04 · Source cna@sap.com
Description
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CWE-434
CISA Known-Exploited Vulnerability
Product: SAP — NetWeaver
Name: SAP NetWeaver Unrestricted File Upload Vulnerability
Date added: 2025-04-29 · Due: 2025-05-20
USED IN RANSOMWARE
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
References
- https://me.sap.com/notes/3594142
- https://url.sap/sapsecuritypatchday
- https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/
- https://www.bleepingcomputer.com/news/security/sap-fixes-suspected-netweaver-zero-day-exploited-in-attacks/
- https://www.theregister.com/2025/04/25/sap_netweaver_patch/
- https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-31324

