CVE ID
CVE-2025-31324
Vulnerability Name
SAP NetWeaver Unrestricted File Upload Vulnerability
- Project: SAP
- Product: NetWeaver
Date
- Date Added: 2025-04-29
- Due Date: 2025-05-20
Description
SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.
Known To Be Used in Ransomware Campaigns?
Known
Action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Additional Notes
https://me.sap.com/notes/3594142 ; https://nvd.nist.gov/vuln/detail/CVE-2025-31324
Related Security News
- Exploit for critical SAP Netweaver flaws released (CVE-2025-31324, CVE-2025-42999)
- Public Exploit for Chained SAP Flaws Exposes Unpatched Systems to Remote Code Execution
- Hackers Exploit SAP Vulnerability to Breach Linux Systems and Deploy Auto-Color Malware
- Hackers exploit SAP NetWeaver bug to deploy Linux Auto-Color malware
- China-Linked Hackers Exploit SAP and SQL Server Flaws in Attacks Across Asia and Brazil
- Chinese Hackers Exploit Ivanti EPMM Bugs in Global Enterprise Network Attacks
- Ransomware gangs join ongoing SAP NetWeaver attacks
- BianLian and RansomExx Exploit SAP NetWeaver Flaw to Deploy PipeMagic Trojan
- China-Linked APTs Exploit SAP CVE-2025-31324 to Breach 581 Critical Systems Worldwide
- Chinese hackers behind attacks targeting SAP NetWeaver servers
Top comments (0)