SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
Is CVE-2025-31324 exploited?
Listed in the CISA KEV catalog on 2025-04-29.
Federal remediation due 2025-05-20.
Past that date by 452 days.
Used in ransomware campaigns.
EPSS puts exploitation in the next 30 days at 99.5%.
Public exploit code: none found in monitored sources.