CVE-2025-31324
Missing Authorization check in SAP NetWeaver (Visual Composer development server)
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- March 27, 2025
- Published Date
- April 24, 2025
- Last Updated
- April 26, 2025
- Vendor
- SAP_SE
- Product
- SAP NetWeaver (Visual Composer development server)
- Description
- SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
- Tags
- Score
- 78.65% (Percentile: 98.97%) as of 2025-05-23
- Exploitation
- none
- Automatable
- Yes
- Technical Impact
- total
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS Score
SSVC Information
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
Tenable Blog | 2025-04-25 00:00:00 UTC |
Recent Mentions
Threat Brief: CVE-2025-31324 (Updated May 23)
Source: Palo Alto Unit42 • Published: 2025-05-23 10:00:14 UTC
Threat Briefing Report: Critical SAP Vulnerabilities (CVE-2025-31324 and CVE-2025-42999) Under Active Mass Exploitation
Source: Onapsis • Published: 2025-05-15 17:28:14 UTC
Critical SAP NetWeaver Vuln Faces Barrage of Cyberattacks
Source: Dark Reading • Published: 2025-05-15 17:02:50 UTC
Follow-up: Second Zero-Day Vulnerability Impacting SAP Netweaver Exploited in the Wild (CVE-2025-42999)
Source: Arctic Wolf • Published: 2025-05-14 20:10:28 UTC
BianLian and RansomExx Exploit SAP NetWeaver Flaw to Deploy PipeMagic Trojan
Source: TheHackerNews • Published: 2025-05-14 17:50:00 UTC
China-Linked APTs Exploit SAP CVE-2025-31324 to Breach 581 Critical Systems Worldwide
Source: TheHackerNews • Published: 2025-05-13 15:13:00 UTC
Critical SAP Zero-Day Vulnerability Under Active Exploitation (CVE-2025-31324)
Source: Onapsis • Published: 2025-05-13 13:03:33 UTC
Onapsis and Mandiant: Latest Intelligence on Critical SAP Zero-Day Vulnerability (CVE-2025-31324)
Source: Onapsis • Published: 2025-05-13 12:59:55 UTC
Threat Brief: CVE-2025-31324
Source: Palo Alto Unit42 • Published: 2025-05-09 22:00:14 UTC
Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell
Source: TheHackerNews • Published: 2025-05-09 04:29:00 UTC
CVE-2025-31324
Source: Horizon3.ai Attack Research • Published: 2025-04-29 15:54:15 UTC
CISA Adds One Known Exploited Vulnerability to Catalog
Source: All CISA Advisories • Published: 2025-04-29 12:00:00 UTC
SAP NetWeaver Visual Composer Flaw Under Active Exploitation
Source: Dark Reading • Published: 2025-04-28 21:26:28 UTC
Active exploitation of SAP NetWeaver Visual Composer CVE-2025-31324
Source: Rapid7 • Published: 2025-04-28 11:57:12 UTC
CVE-2025-31324: Zero-Day Vulnerability in SAP NetWeaver Exploited in the Wild
Source: Tenable Blog • Published: 2025-04-25 16:00:24 UTC
Scanner Integrations
Scanner | URL | Date Detected |
---|---|---|
Nuclei | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-31324.yaml | 2025-04-26 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
Onapsis/Onapsis-Mandiant-CVE-2025-31324-Vuln-Compromise-Assessment
Type: github • Created: 2025-05-01 18:44:20 UTC • Stars: 0
JonathanStross/CVE-2025-31324
Type: github • Created: 2025-04-30 22:31:53 UTC • Stars: 0
nullcult/CVE-2025-31324-File-Upload
Type: github • Created: 2025-04-30 13:39:30 UTC • Stars: 0
BlueOWL-overlord/Burp_CVE-2025-31324
Type: github • Created: 2025-04-30 06:34:12 UTC • Stars: 0
Pengrey/CVE-2025-31324
Type: github • Created: 2025-04-29 09:46:53 UTC • Stars: 0
abrewer251/CVE-2025-31324_PoC_SAP
Type: github • Created: 2025-04-29 00:16:06 UTC • Stars: 0
ODST-Forge/CVE-2025-31324_PoC
Type: github • Created: 2025-04-28 20:32:21 UTC • Stars: 0
Alizngnc/SAP-CVE-2025-31324
Type: github • Created: 2025-04-28 13:19:54 UTC • Stars: 0
moften/CVE-2025-31324-NUCLEI
Type: github • Created: 2025-04-28 01:43:22 UTC • Stars: 0
moften/CVE-2025-31324
Type: github • Created: 2025-04-28 01:32:39 UTC • Stars: 0
Totunm/CVE-2025-31324
Type: github • Created: 2025-04-27 20:12:02 UTC • Stars: 0
Onapsis/Onapsis_CVE-2025-31324_Scanner_Tools
Type: github • Created: 2025-04-27 16:40:45 UTC • Stars: 0
redrays-io/CVE-2025-31324
Type: github • Created: 2025-04-27 11:39:26 UTC • Stars: 0
rxerium/CVE-2025-31324
Type: github • Created: 2025-04-25 15:22:59 UTC • Stars: 3
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel
-
Detected by Nuclei
-
Proof of Concept Exploit Available
-
Used in China-Nexus APT Campaign