THREAT OPS › CVEs › CVE-2025-31324
CVE-2025-31324 — SAP NetWeaver Unrestricted File Upload Vulnerability
SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.
Vulnerability details
- Affected productsNetWeaver
- KEV remediation due2025-05-20
Related reporting
- August 2026 CVE Landscaperecordedfuture
- [NVD] CVE-2025-31324 (CRITICAL 10.0) — SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integritnvd