CVE-2025-31324 – SAP NetWeaver Unauthenticated Remote Code Execution

The following table lists the changes that have been made to the
CVE-2025-31324 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Apr. 24, 2025

    Action Type Old Value New Value
    Added Description SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
    Added CVSS V3.1 AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
    Added CWE CWE-434
    Added Reference https://me.sap.com/notes/3594142
    Added Reference https://url.sap/sapsecuritypatchday
Share the Post:

Related Posts