PromptRiskDBThreat intelligence atlas

CVE-2025-31324 - SAP NetWeaver

AI Vulnerability Context

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.

Overview

A source-backed snapshot of this vulnerability.

CISA KEVyesWhether CISA lists this as exploited.
Techniques0AI attack methods connected to this vulnerability.
Case studies0Examples where this vulnerability is mentioned.

Vulnerability status

How serious this vulnerability is and whether it is known to be exploited.

CISA KEVCRITICAL
CVE ID
CVE-2025-31324
Vendor/project
SAP
Product
NetWeaver
Vulnerability name
SAP NetWeaver Unrestricted File Upload Vulnerability
Date added
2025-04-29
Due date
2025-05-20
Known ransomware campaign use
Known
CVSS v3
10.0
CWE-434

Exploit context

What the vulnerability is about.

No description available. The source record only contains identifiers and metadata.

Source evidence

Original public records and references for this page.

Original source

Original source links

Open the public records and source datasets used for this page.