CVE-2025-31324CRITICAL 9.8CISA KEVEPSS p99.9%
CVE-2025-31324SAP NetWeaver Unrestricted File Upload Vulnerability
SAP / NetWeaver
Description
SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.
Scoring
| CVSS 3.1 | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 99.32% probability of exploitation · percentile 99.9% · 2026-06-17T12:03:21Z |
| Published | 2025-04-24 |
| Last modified | 2025-10-31 |
CISA KEV entry
Added to KEV: 2025-04-29
Underlying weaknesses· 1
References
- https://me.sap.com/notes/3594142
- https://url.sap/sapsecuritypatchday
- https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/
- https://www.bleepingcomputer.com/news/security/sap-fixes-suspected-netweaver-zero-day-exploited-in-attacks/
- https://www.theregister.com/2025/04/25/sap_netweaver_patch/
- https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-31324
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Unrestricted Upload of File with Dangerous Typecwe-434 | 0% | live |
(incoming)1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| KEVEntry | SAP NetWeaver Unrestricted File Upload Vulnerabilitykev-cve-2025-31324 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.