SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
History

Fri, 02 May 2025 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Sap
Sap netweaver
CPEs cpe:2.3:a:sap:netweaver:7.50:*:*:*:*:*:*:*
Vendors & Products Sap
Sap netweaver

Fri, 02 May 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2025-04-29'}


Thu, 01 May 2025 21:15:00 +0000


Tue, 29 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 26 Apr 2025 01:45:00 +0000


Thu, 24 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 24 Apr 2025 17:00:00 +0000

Type Values Removed Values Added
Description SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
Title Missing Authorization check in SAP NetWeaver (Visual Composer development server)
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-04-24T16:50:27.706Z

Updated: 2025-05-02T17:13:30.650Z

Reserved: 2025-03-27T23:02:06.906Z

Link: CVE-2025-31324

cve-icon Vulnrichment

Updated: 2025-05-02T17:13:30.650Z

cve-icon NVD

Status : Modified

Published: 2025-04-24T17:15:35.913

Modified: 2025-05-02T18:15:26.530

Link: CVE-2025-31324

cve-icon Redhat

No data.