CVE-2025-31324
This vulnerability allows an unauthenticated attacker to upload malicious binaries to SAP NetWeaver Visual Composer Metadata Uploader, potentially compromising the system's confidentiality, integrity, and availability. It affects SAP NetWeaver 7.50 and has a CVSS score of 10.
An official fix is available, so this entry is kept for 30 days and then removed automatically.
Who is affected
SAP NetWeaver 7.50 users, especially those running the Visual Composer Metadata Uploader component.
Real-world impact
An attacker could upload and execute malicious binaries, leading to full system compromise, data theft, and service disruption.
Why this severity
The CVSS score of 10 reflects that the vulnerability is exploitable over the network with no authentication, and an attacker can fully compromise confidentiality, integrity, and availability.
What to do about it
- 01Apply the vendor’s recommended mitigations as described in the official instructions.
- 02Follow BOD 22-01 guidance if the system is hosted in a cloud environment.
- 03If no mitigations are available, discontinue use of the product.
CISA KEV required action
Timeline
- Apr 24, 2025 · Apr 24, 2025PublishedDisclosed and added to the National Vulnerability Database.
- Apr 29, 2025 · Apr 29, 2025Confirmed exploited (CISA KEV)CISA added it to the Known Exploited Vulnerabilities catalog — attackers are using it in the wild.
- May 20, 2025 · May 20, 2025CISA remediation deadlineFederal agencies are required to remediate by this date.
- Aug 4, 2026 · 2d agoAdvisory updatedThe NVD record was last revised.
- Aug 4, 2026 · 2d agoOfficial fix availableA vendor patch or mitigation now exists — see the remediation steps above.
How it’s attacked
References & advisories
- me.sap.com/notes/3594142permissions required
- url.sap/sapsecuritypatchdayvendor advisory
- onapsis.com/blog/active-exploitation-of…third party advisory
- bleepingcomputer.com/news/security/sap-fixes-sus…press/media coverage
- theregister.com/2025/04/25/sap_netweaver_pa…press/media coverage
- cisa.gov/known-exploited-vulnerabili…us government resource