First published: Thu Apr 24 2025(Updated: )
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-31324 is considered critical due to the potential for unauthenticated code execution on affected systems.
To mitigate CVE-2025-31324, it is essential to apply the latest security patches provided by SAP for NetWeaver.
CVE-2025-31324 affects SAP NetWeaver versions that utilize the Visual Composer Metadata Uploader.
CVE-2025-31324 is associated with unauthorized file uploads leading to potential remote code execution.
Exploitation of CVE-2025-31324 could result in severe harm to the host system, including loss of data integrity and confidentiality.