logo

Critical SAP NetWeaver Vulnerability (CVE-2025-31324) Allows Unauthorized Upload of Malicious Executables

ID: 0514b642-f46e-5627-ade9-d7046ecd2def

STIX ID: report--0514b642-f46e-5627-ade9-d7046ecd2def

Feed Name: SOCRadar Blog

Threat Score
90/100

Date Published: 2025-04-26

Date Updated: 2026-04-30

Author: Mert Öbek

...
...

Critical unauthenticated file-upload vulnerability CVE-2025-31324 in SAP NetWeaver Visual Composer (v7.50) with CVSS 10.0 is being actively exploited to upload webshells and achieve remote code execution; SAP issued an emergency patch and organizations are advised to apply it, restrict or disable the metadata uploader endpoint, scan for unauthorized files and webshells, and monitor listed reconnaissance IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.