Visual Composer: SAP NetWeaver Visual Composer Metadata Uploader unrestricted file upload (CVE-2025-31324) (CVE-2025-31324) #shorts

Summary

In this episode, we dive into CVE-2025-31324, a critical zero-day vulnerability in SAP NetWeaver Visual Composer that is being actively exploited in the wild. We’ll cover what’s at risk, how the flaw works, and what organizations need to do right now to protect their systems.

Product details

The vulnerability resides in the SAP NetWeaver Visual Composer Metadata Uploader, specifically version VCFRAMEWORK 7.50. This component is used by developers to import metadata and models into the Visual Composer design environment. SAP has released an out-of-band security patch to address this issue.

Vulnerability type summary

CVE-2025-31324 is classified under CWE-434: Unrestricted Upload of File with Dangerous Type. In essence, the uploader lacks proper authorization checks, allowing unauthenticated users to send arbitrary executable files to the server.

Details of the vulnerability

An attacker can exploit the missing authorization in the metadata uploader to upload malicious binaries directly to the host. Once uploaded, these executables can be triggered on the server, leading to remote code execution, full system compromise, and potential lateral movement across the network. Reports indicate active exploitation, making this a high-priority patch for all affected environments.

Conclusion

Organizations using SAP NetWeaver Visual Composer should immediately apply the out-of-band patch provided by SAP. Review access logs for suspicious upload attempts, restrict inbound traffic to the uploader endpoint, and ensure all development servers are isolated. Prompt remediation will prevent attackers from gaining a foothold and protect the confidentiality, integrity, and availability of your SAP landscape.

Watch the full video on YouTube: CVE-2025-31324

Remediation and exploitation details

This chain involves the following actors

This following systems are involved

Attack entry point

Remediation actions

Exploitation actions

Related Content

NOTE: The following related content has not been vetted and may be unsafe.

CVE database technical details

CVE ID
CVE-2025-31324
Description
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
Provider
sap
CWE / problem types
CWE-434: Unrestricted Upload of File with Dangerous Type
Affected Software Versions
SAP_SE:SAP NetWeaver (Visual Composer development server):[{'status': 'affected', 'version': 'VCFRAMEWORK 7.50'}]
Date Published
2025-04-24T16:50:27.706Z
Last Updated
2025-05-02T17:13:30.650Z