CRITICAL

CVE-2025-31324

Sap Netweaver 2025-04-24 CVSS v3.1
CVSS
9.8
KEV

Description

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.

Summary dbcve.org

SAP NetWeaver Visual Composer Metadata Uploader lacks proper authorization checks, allowing unauthenticated attackers to upload potentially malicious executable binaries directly to the server. This can lead to remote code execution, enabling full compromise of the host system and the SAP environment.

Mitigation

Restrict network access to the Visual Composer Metadata Uploader endpoint (typically /VC_MetadataUploader) until an official SAP patch is available; consider disabling the component if unused or implementing WAF rules to block executable upload attempts.

Weakness (CWE)

CWE-434 Unrestricted File Upload

EPSS Score

99.47%
Probability of exploitation in next 30 days
99.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE