Known vulnerability record

CVE-2025-31324

SAP NetWeaver Unrestricted File Upload Vulnerability

Stable IDcve:CVE-2025-31324Last updatedLast verifiedLegacy review pendingProvenanceCISA KEV + CVE record + EPSS

SAP NetWeaver Unrestricted File Upload Vulnerability

SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.

Keep the signals separate

CVSS severitycriticalScore 10 · source sap
EPSS probability99.5%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2025-04-29
Ransomware useknownPreserved as known / unknown, not a truthy default

Dates and provenance

CVE published
2025-04-24
CVE modified
2026-08-04
KEV date added
2025-04-29
Dataset fetched
2026-08-21T03:55:08.338Z

Original records

Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.