CVE-2025-31324

unknown KEV
Published 2025-04-29 · Modified 2025-04-29
CVSS v3
CVSS v2
VIR risk
1.5

Description

SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.

CISA KEV

Vendor
SAP
Product
NetWeaver
Due date
2025-05-20

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://me.sap.com/notes/3594142 ; https://nvd.nist.gov/vuln/detail/CVE-2025-31324

Exploits

References

Verify integrity in audit chain (admin only). AS-IS.