SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2025-31324

SAP NetWeaver Unrestricted File Upload Vulnerability

KEVCRITICAL 9.8EPSS 99.5%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 20 May 2025). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
99.51% probability · 100th percentile
CISA KEV
Listed 29 April 2025 · due 20 May 2025 · used in ransomware campaigns
Weakness
CWE-434
Affected
sap/netweaver
Source
cna@sap.com

CISA notes

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. https://me.sap.com/notes/3594142 ; https://nvd.nist.gov/vuln/detail/CVE-2025-31324

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.