SAP NetWeaver Unrestricted File Upload Vulnerability
Critical CVSS 10.0 Listed in CISA KEV
Summary
SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.
In-depth triage · Auto channel
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- SAP:NetWeaver
- :
Sources
- CISA KEV DATABASE
- NVD DATABASE
Original Links
- https://nvd.nist.gov/vuln/detail/CVE-2025-31324 advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog kev
- https://me.sap.com/notes/3594142 reference
- https://url.sap/sapsecuritypatchday Vendor Advisory
- https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/ Third Party Advisory
- https://www.bleepingcomputer.com/news/security/sap-fixes-suspected-netweaver-zero-day-exploited-in-attacks/ Press/Media Coverage
- https://www.theregister.com/2025/04/25/sap_netweaver_patch/ Press/Media Coverage
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-31324 US Government Resource
Timeline
- kev_added CISA KEV
- kev_ingest CISA KEV
- nvd_ingest NVD