Missing Authorization check in SAP NetWeaver (Visual Composer development server)
Summary
| CVE | CVE-2025-31324 |
|---|---|
| State | PUBLISHED |
| Assigner | sap |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-04-24 17:15:35 UTC |
| Updated | 2026-08-04 05:16:34 UTC |
| Description | SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system. |
Risk And Classification
Primary CVSS: v3.1 9.8 CRITICAL from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS: 0.995120000 probability, percentile 0.999420000 (date 2026-08-21)
CISA KEV: Listed on 2025-04-29; due 2025-05-20; ransomware use Known
Problem Types: CWE-434 | CWE-434 CWE-434: Unrestricted Upload of File with Dangerous Type
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 9.8 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 3.1 | [email protected] | Secondary | 10 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | CNA | CVSS | 10 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA Known Exploited Vulnerability
| Vendor | SAP |
|---|---|
| Product | NetWeaver |
| Name | SAP NetWeaver Unrestricted File Upload Vulnerability |
| Required Action | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
| Notes | https://me.sap.com/notes/3594142 ; https://nvd.nist.gov/vuln/detail/CVE-2025-31324 |
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | SAP SE | SAP NetWeaver Visual Composer Development Server | affected VCFRAMEWORK 7.50 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| me.sap.com/notes/3594142 | [email protected] | me.sap.com | Permissions Required |
| www.theregister.com/2025/04/25/sap_netweaver_patch | af854a3a-2127-422b-91ae-364da2661108 | www.theregister.com | Press/Media Coverage |
| onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | onapsis.com | Third Party Advisory |
| url.sap/sapsecuritypatchday | [email protected] | url.sap | Vendor Advisory |
| www.bleepingcomputer.com/news/security/sap-fixes-suspected-netweaver-zero-day-exploite... | af854a3a-2127-422b-91ae-364da2661108 | www.bleepingcomputer.com | Press/Media Coverage |
| www.cisa.gov/known-exploited-vulnerabilities-catalog | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | www.cisa.gov | US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2025-04-29T00:00:00.000Z | CVE-2025-31324 added to CISA KEV |
There are currently no legacy QID mappings associated with this CVE.