EXPOSURES › CVE-2025-31324
CVE-2025-31324
CRITICAL ⌖ ON CISA KEV · EXPLOITEDAn unauthenticated attacker can upload malicious executables via SAP NetWeaver's Visual Composer Metadata Uploader, enabling remote code execution and ransomware deployment.
SAP NetWeaver's unrestricted file upload flaw allows unauthenticated agents to deploy malicious binaries, directly enabling remote code execution and ransomware attacks. DIB organizations must patch this critical vulnerability immediately, as it bypasses authentication controls and violates CMMC/NIST 800-171 requirements for preventing unauthorized access and malicious code execution. Failure to patch exposes the organization to supply-chain compromise and data exfiltration.
Shame score — A critical, actively exploited vulnerability allowing unauthenticated remote code execution and ransomware deployment represents a severe, avoidable failure in secure software design and patch management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.
| PRODUCT | STATUS |
|---|---|
| SAP NS2 Cloud Intelligent Enterprise SAP National Security Services Inc. (SAP NS2) |
Authorized |
| SAP NS2 Secure Node with SuccessFactors Suite - DoD SAP National Security Services Inc. (SAP NS2) |
Authorized |