cvedb.io
CVE-2025-31324
CRITICAL · CVSS 10 ⚠ KEV — EXPLOITED
EPSS exploitation probability: 100%
⚠ Listed in the CISA Known Exploited Vulnerabilities catalog — actively exploited.
Published 2025-04-29 · Last modified 2026-08-04T05:16:34.557

Summary

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.

Affected products

SAP — NetWeaver

Does this affect you?

Add your gear to cvedb and we'll alert you only when SAP ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.