LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-31324: SAP NetWeaver Unrestricted File Upload Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 29, 2025
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 20, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-31324 to its Known Exploited Vulnerabilities catalog on Apr 29, 2025, with a federal patch deadline of May 20, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.

CVE-2025-31324 is an unrestricted file upload vulnerability affecting SAP NetWeaver, specifically the Visual Composer Metadata Uploader component. An unauthenticated attacker can upload potentially malicious executable binaries to the system.

This class of flaw matters because it can enable an attacker to place executable content on a critical enterprise platform without credentials, opening a path to further compromise. Public reporting indicates known ransomware use of this vulnerability, so organizations running SAP NetWeaver should treat it as high priority and confirm all details against the vendor advisory.

How it works

The underlying weakness is CWE-434: unrestricted upload of a file with a dangerous type. In this case the affected component accepts file uploads without adequate authentication or content restrictions. An unauthenticated agent can therefore submit executable binaries that the system may store or process in a way that later allows execution or further abuse.

Attackers typically target such upload endpoints to drop web shells, malware loaders, or other payloads that give them a foothold inside the application server. Exact request formats, file-type bypasses, or post-upload execution paths are not detailed in the available summary; defenders must consult the vendor advisory for precise technical indicators rather than relying on generic assumptions.

Am I affected? How to find it in your systems

SAP NetWeaver is commonly deployed as the application and integration platform for SAP business suites, often in on-premises data centers or private cloud environments that host ERP, CRM, or custom Visual Composer applications. The vulnerable surface is the Visual Composer Metadata Uploader.

Because exact affected versions and configuration prerequisites are not supplied here, treat any NetWeaver system with Visual Composer as potentially in scope until the vendor advisory is checked.

How to remediate

The primary action is to apply the vendor-supplied update or mitigation for CVE-2025-31324 as soon as it is available and tested in your environment. Follow the SAP security note or advisory instructions exactly; do not rely on third-party summaries for patch identifiers or version ranges.

If you can't patch immediately

Until the vendor update can be deployed, reduce exposure with layered compensating controls.

These measures lower risk but do not replace the vendor patch. Continue tracking the advisory for permanent remediation steps.

If your data may have been exposed

Actively exploited vulnerabilities of this type, especially those with known ransomware use, frequently lead to broader breaches once an attacker gains a foothold. If you discover evidence of exploitation or cannot rule out compromise, treat the incident as a potential data-exposure event: isolate affected systems, preserve logs, and engage your incident-response process. You can also run a free exposure scan of your email addresses against known breach data sets to check whether credentials or personal information associated with your organization have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSAP · NetWeaver
WeaknessCWE-434
Added to CISA KEVApr 29, 2025
Federal patch deadlineMay 20, 2025
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities