CVE-2025-31324
CVSS 3.1 Score 9.8 of 10 (high)
Details
Published Apr 24, 2025
Updated: May 6, 2025
CWE ID 434
Summary
CVE-2025-31324 refers to a vulnerability in SAP NetWeaver Visual Composer Metadata Uploader. This issue allows unauthenticated agents to upload executable binaries without proper authorization checks. Malicious code embedded in these binaries could lead to severe harm, compromising the confidentiality, integrity, and availability of the affected system. The absence of suitable authentication mechanisms enables this attack, making it a significant threat to targeted systems.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- SAP Net Weaver
Affected Vendors
- SAP SE