CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2025-31324

KEV · ransomware Critical · CVSS 10.0
CVSS
10.0
nvd
EPSS
KEV
Listed
ransomware
Class
other
CWE-434

Description

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.

References

Status: profiled · ingested 2026-08-04T06:00:54.000Z