Critical SAP NetWeaver Vulnerability (CVE-2025-31324) Allows Unauthorized Upload of Malicious Executables
ID: 0514b642-f46e-5627-ade9-d7046ecd2def
STIX ID: report--0514b642-f46e-5627-ade9-d7046ecd2def
Feed Name: SOCRadar Blog
Threat Score
Critical unauthenticated file-upload vulnerability CVE-2025-31324 in SAP NetWeaver Visual Composer (v7.50) with CVSS 10.0 is being actively exploited to upload webshells and achieve remote code execution; SAP issued an emergency patch and organizations are advised to apply it, restrict or disable the metadata uploader endpoint, scan for unauthorized files and webshells, and monitor listed reconnaissance IPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
