CVE-2025-31324 KEV
10.0
CRITICAL · CVSS 3.1 · EPSS 99.5% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2025-05-20.
Description
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
Scoring
| CVSS | 10.0 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| EPSS | 99.47% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-434 |
| On CISA KEV | yes — remediate by 2025-05-20 |
| Public exploit | none known |
| Published | 2025-04-24 |
| Last modified | 2026-08-04 |
CISA KEV
| Name | SAP NetWeaver Unrestricted File Upload Vulnerability |
|---|---|
| Added | 2025-04-29 |
| Due | 2025-05-20 |
| Vendor / product | SAP / NetWeaver |
| Ransomware use | known |
Affected (1)
| Vendor | Product |
|---|---|
| sap | netweaver |
References
- https://me.sap.com/notes/3594142
- https://url.sap/sapsecuritypatchday
- https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/
- https://www.bleepingcomputer.com/news/security/sap-fixes-suspected-netweaver-zero-day-exploited-in-attacks/
- https://www.theregister.com/2025/04/25/sap_netweaver_patch/
- https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-31324
→ the Explorer · watch your stack · NVD