logo

A Vulnerability in SAP NetWeaver Visual Composer Could Allow for Remote Code Execution

ID: 2912d4ee-757d-5e7d-9f41-9fd3f39dafda

STIX ID: report--2912d4ee-757d-5e7d-9f41-9fd3f39dafda

Feed Name: CISecurity.org Advisories

Threat Score
70/100

Date Published: 2025-04-25

Date Updated: 2026-04-27

...
...

A vulnerability (CVE-2025-31324) in SAP NetWeaver Visual Composer Metadata Uploader allows unauthenticated attackers to upload executable binaries, enabling remote code execution; the issue is mapped to MITRE ATT&CK T1190 (Exploit Public-Facing Application) and could severely impact confidentiality, integrity, and availability.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.