CVE-2025-31324

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 24, 2025
Updated: May 6, 2025
CWE ID 434

Summary

CVE-2025-31324 refers to a vulnerability in SAP NetWeaver Visual Composer Metadata Uploader. This issue allows unauthenticated agents to upload executable binaries without proper authorization checks. Malicious code embedded in these binaries could lead to severe harm, compromising the confidentiality, integrity, and availability of the affected system. The absence of suitable authentication mechanisms enables this attack, making it a significant threat to targeted systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share