April 29, 2025 · Applied Cybernetics Group
CVE-2025-31324 — SAP NetWeaver
known ransomware use
SAP NetWeaver Unrestricted File Upload Vulnerability
- Added to KEV
2025-04-29- Federal due date
2025-05-20- Vendor
- SAP
- Product
- NetWeaver
- EPSS
- 99.9th percentile (score 0.995, as of
2026-09-16) - NVD CVSS v3.1
- 10 (CRITICAL)
- Ransomware use
- Known
- ATT&CK
- T1055 , T1059 , T1505.003 , T1602 · signal rollup
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2025-31324
CISA short description
SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
NVD description
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.