CVE-2025-31324
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
- Published
- Apr 24, 2025
- Updated
- Aug 4, 2026
- Assigning CNA
- sap
- Evidence observed
- Apr 29, 2025
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.9%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
Sources
18Proof-of-Concept for CVE-2025-31324: Unauthenticated upload in SAP NetWeaver Visual Composer Metadata Uploader
Proof-of-Concept 0day for SAP NetWeaver created by ShinyHunters
- Burp_CVE-2025-31324Scanner
Python-based Burp Suite extension is designed to detect the presence of CVE-2025-31324
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.