Known vulnerability record
CVE-2025-31324
SAP NetWeaver Unrestricted File Upload Vulnerability
Summary
SAP NetWeaver Unrestricted File Upload Vulnerability
SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.
Signals
Keep the signals separate
CVSS severitycriticalScore 10 · source sap
EPSS probability99.5%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2025-04-29
Ransomware useknownPreserved as known / unknown, not a truthy default
Timeline
Dates and provenance
- CVE published
- 2025-04-24
- CVE modified
- 2026-08-04
- KEV date added
- 2025-04-29
- Dataset fetched
- 2026-08-21T03:55:08.338Z
Sources
Original records
- https://www.cve.org/CVERecord?id=CVE-2025-31324 ↗
- https://nvd.nist.gov/vuln/detail/CVE-2025-31324 ↗
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-31324 ↗
Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.