Unauthorized Metadata Upload Vulnerability in SAP NetWeaver Visual Composer by SAP
CVE-2025-31324

9.8CRITICAL

Key Information:

Vendor

SAP

Vendor
CVE Published:
24 April 2025

Badges

🥇 Trended No. 1📈 Trended📈 Score: 26,300💰 Ransomware👾 Exploit Exists🟡 Public PoC🟣 EPSS 78%🦅 CISA Reported📰 News Worthy

What is CVE-2025-31324?

CVE-2025-31324 is a critical vulnerability identified in SAP NetWeaver's Visual Composer component, which is widely used by organizations to develop applications without extensive coding. This vulnerability stems from a lack of proper authorization checks in the Metadata Uploader feature, specifically accessible through the /developmentserver/metadatauploader endpoint. As a result, unauthenticated individuals can exploit this weakness to upload arbitrary and potentially malicious files to the server, which can lead to severe consequences such as remote code execution and complete system compromise. Given that many businesses rely on SAP NetWeaver for critical operations, this vulnerability poses a significant risk to the confidentiality, integrity, and availability of their systems.

The exploitation process involves sending specially crafted HTTP requests to the vulnerable endpoint, enabling attackers to upload files, including web shells, which allow them to execute commands on the server with administrative privileges. This scenario compromises not only the SAP environment but also any sensitive data contained within it, making timely remediation essential.

Potential impact of CVE-2025-31324

  1. Unauthorized Remote Code Execution: Attackers can exploit this vulnerability to execute unauthorized commands on the SAP NetWeaver server, enabling them to take full control of the affected systems. This action can lead to data theft, unauthorized data manipulation, and further penetration into the organization's network.

  2. Increased Risk of Data Breaches: With the ability to upload malicious files, attackers can facilitate data breaches that may expose sensitive company and customer information. Such incidents can have compliance repercussions and damage the organization’s reputation.

  3. System Downtime and Operational Disruption: The successful exploitation of this vulnerability can lead to prolonged system downtimes due to malware deployment, remediation efforts, and potential recovery processes. This disruption can affect business operations and lead to significant financial losses.

CISA has reported CVE-2025-31324

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2025-31324 as being exploited and is known by the CISA as enabling ransomware campaigns.

The CISA's recommendation is: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Affected Version(s)

SAP NetWeaver (Visual Composer development server) VCFRAMEWORK 7.50

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

News Articles

Ransomware groups join attacks on SAP NetWeaver

Administrators are strongly advised to update their SAP NetWeaver servers quickly or disable the Visual Composer component.

4 days ago

Critical SAP NetWeaver Vuln Faces Barrage of Cyberattacks

As threat actors continue to hop on the train of exploiting CVE-2025-31324, researchers are recommending that SAP administrators patch as soon as possible so that they don't fall victim next.

1 week ago

SAP Flaw Exploited by Ransomware Groups and Chinese-Backed Hackers

The critical vulnerability is being exploited by BianLian, RansomwEXX and a Chinese nation-state actor known as Chaya_004

1 week ago

References

EPSS Score

78% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟡

    Public PoC available

  • 🥇

    Vulnerability reached the number 1 worldwide trending spot

  • 📈

    Vulnerability started trending

  • 🦅

    CISA Reported

  • 💰

    Used in Ransomware

  • 👾

    Exploit known to exist

  • 📰

    First article discovered by SecurityWeek

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-31324 : Unauthorized Metadata Upload Vulnerability in SAP NetWeaver Visual Composer by SAP