/Vulnerability Library

SAP NetWeaver Visual Composer Metadata Uploader - Deserialization

CVE-2025-31324
Verified

Description

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.

Severity

Critical

CVSS Score

10

Exploit Probability

99%

Published Date

April 26, 2025

Template Author

iamnoooob, rootxharsh, parthmalhotra
+1

CVE-2025-31324.yaml
10.0Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVE ID:
cve-2025-31324
CWE ID:
cwe-434

References

https://www.bleepingcomputer.com/news/security/sap-fixes-suspected-netweaver-zero-day-exploited-in-attacks/https://www.theregister.com/2025/04/25/sap_netweaver_patch/https://me.sap.com/notes/3594142https://url.sap/sapsecuritypatchday

Remediation Steps

Apply SAP security note 3594142 and upgrade to the latest patched version of SAP NetWeaver Visual Composer.