Skip to content
COOEY

EXPOSURES › CVE-2025-31324

CVE-2025-31324

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-04-29 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-31324 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

An unauthenticated attacker can upload malicious executables via SAP NetWeaver's Visual Composer Metadata Uploader, enabling remote code execution and ransomware deployment.

SAP NetWeaver's unrestricted file upload flaw allows unauthenticated agents to deploy malicious binaries, directly enabling remote code execution and ransomware attacks. DIB organizations must patch this critical vulnerability immediately, as it bypasses authentication controls and violates CMMC/NIST 800-171 requirements for preventing unauthorized access and malicious code execution. Failure to patch exposes the organization to supply-chain compromise and data exfiltration.

Shame score — A critical, actively exploited vulnerability allowing unauthenticated remote code execution and ransomware deployment represents a severe, avoidable failure in secure software design and patch management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
SAP NS2 Cloud Intelligent Enterprise
SAP National Security Services Inc. (SAP NS2)
Authorized
SAP NS2 Secure Node with SuccessFactors Suite - DoD
SAP National Security Services Inc. (SAP NS2)
Authorized