A AegiFlow
UNKNOWNKNOWN EXPLOITEDRANSOMWARE: KNOWN

CVE-2025-31324

SAP NetWeaver Unrestricted File Upload Vulnerability

Published
2025-04-29
Modified
2026-07-31
Sources
cisa-kev

Summary

SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.