CVE-2025-31324
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- March 27, 2025
- Published Date
- April 24, 2025
- Last Updated
- April 26, 2025
- Vendor
- SAP_SE
- Product
- SAP NetWeaver (Visual Composer development server)
- Description
- SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
- Score
- 7.32% (Percentile: 91.16%) as of 2025-04-29
SSVC Information
- Exploitation
- none
- Automatable
- Yes
- Technical Impact
- total
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
Tenable Blog | 2025-04-25 00:00:00 UTC |
Recent Mentions
CVE-2025-31324
Source: Horizon3.ai Attack Research • Published: 2025-04-29 15:54:15 UTC
CISA Adds One Known Exploited Vulnerability to Catalog
Source: All CISA Advisories • Published: 2025-04-29 12:00:00 UTC
SAP NetWeaver Visual Composer Flaw Under Active Exploitation
Source: Dark Reading • Published: 2025-04-28 21:26:28 UTC
Active exploitation of SAP NetWeaver Visual Composer CVE-2025-31324
Source: Rapid7 • Published: 2025-04-28 11:57:12 UTC
CVE-2025-31324: Zero-Day Vulnerability in SAP NetWeaver Exploited in the Wild
Source: Tenable Blog • Published: 2025-04-25 16:00:24 UTC
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-31324.yaml | 2025-04-26 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
BlueOWL-overlord/Burp_CVE-2025-31324
Type: github • Created: 2025-04-30 06:34:12 UTC • Stars: 0
Pengrey/CVE-2025-31324
Type: github • Created: 2025-04-29 09:46:53 UTC • Stars: 0
abrewer251/CVE-2025-31324_PoC_SAP
Type: github • Created: 2025-04-29 00:16:06 UTC • Stars: 0
ODST-Forge/CVE-2025-31324_PoC
Type: github • Created: 2025-04-28 20:32:21 UTC • Stars: 0
Alizngnc/SAP-CVE-2025-31324
Type: github • Created: 2025-04-28 13:19:54 UTC • Stars: 0
moften/CVE-2025-31324-NUCLEI
Type: github • Created: 2025-04-28 01:43:22 UTC • Stars: 0
moften/CVE-2025-31324
Type: github • Created: 2025-04-28 01:32:39 UTC • Stars: 0
Totunm/CVE-2025-31324
Type: github • Created: 2025-04-27 20:12:02 UTC • Stars: 0
Onapsis/Onapsis_CVE-2025-31324_Scanner_Tools
Type: github • Created: 2025-04-27 16:40:45 UTC • Stars: 0
redrays-io/CVE-2025-31324
Type: github • Created: 2025-04-27 11:39:26 UTC • Stars: 0
rxerium/CVE-2025-31324
Type: github • Created: 2025-04-25 15:22:59 UTC • Stars: 3