
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
O template realiza uma requisição HTTP GET à URL base do alvo e examina os cabeçalhos de resposta para identificar instâncias do SAP NetWeaver Application Server. Esta informação ajuda a avaliar se o sistema pode ser suscetível ao CVE-2025-31324.
nuclei -u https://yourHost.com -t template.yamlUse por sua conta e risco, não serei responsável por atividades ilegais que você realize em infraestrutura que não possui ou não tem permissão para escanear.
Sinta-se à vontade para entrar em contato comigo no Signal.