CVE-2025-31324
Description
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
Summary dbcve.org
SAP NetWeaver Visual Composer Metadata Uploader lacks proper authorization checks, allowing unauthenticated attackers to upload potentially malicious executable binaries directly to the server. This can lead to remote code execution, enabling full compromise of the host system and the SAP environment.
Mitigation
Restrict network access to the Visual Composer Metadata Uploader endpoint (typically /VC_MetadataUploader) until an official SAP patch is available; consider disabling the component if unused or implementing WAF rules to block executable upload attempts.