CVE-2025-31324
About
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
Rainforest analyst review
SAP NetWeaver's Visual Composer includes a Metadata Uploader endpoint that lacks a proper authorization check. An unauthenticated attacker sends a request to that endpoint and uploads an executable file — typically a web shell — directly onto the application server. With the payload written to a reachable path, the attacker then invokes it to run commands on the host, so a missing access control on one upload handler yields full remote code execution against the SAP system.
SAP NetWeaver underpins ERP and other core business applications, and a compromised server exposes the crown-jewel financial, HR, and operational data those systems process, along with a deep foothold into an enterprise's most trusted infrastructure. This flaw saw rapid, widespread exploitation after disclosure, with web shells deployed on internet-facing NetWeaver instances by multiple actors, and it was added to CISA's KEV catalog quickly. Apply SAP's patch without delay, and because Visual Composer is not needed everywhere, disable it where it is unused. Given the speed of exploitation, hunt exposed servers for unauthorized files in the relevant servlet paths and unexpected server-side processes rather than assuming the patch alone is sufficient.
References
- https://me.sap.com/notes/3594142
- https://url.sap/sapsecuritypatchday
- https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/
- https://www.bleepingcomputer.com/news/security/sap-fixes-suspected-netweaver-zero-day-exploited-in-attacks/
- https://www.theregister.com/2025/04/25/sap_netweaver_patch/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-31324
Related CVEs
Frequently asked questions
What is CVE-2025-31324?
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
How severe is CVE-2025-31324?
CVE-2025-31324 carries a CVSS 3.1 base score of 10, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 100 out of 100, in the critical band.
How is CVE-2025-31324 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2025-31324?
Public advisories list the following as affected: netweaver. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2025-31324?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
