Zurück zur CVE-Übersicht
CVE-2025-31324
CRITICAL(10.0)KEV — Aktiv ausgenutztCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Risk Signal Score85/100 — KRITISCH
- CVSS 10 — Kritisch
- EPSS 100% — sehr wahrscheinlich ausgenutzt
- Im CISA KEV-Katalog (aktiv ausgenutzt)
Erwähnungen (letzte 60 Tage)
Artikel
CISA KEV
Bestätigt ausgenutzt
EPSS-Score
100%
Exploit-Wahrscheinlichkeit (30 Tage)
CVSS Score
10
Technische Schwere
Beschreibung
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
Referenzen
- https://me.sap.com/notes/3594142
- https://url.sap/sapsecuritypatchday
- https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324...
- https://www.bleepingcomputer.com/news/security/sap-fixes-suspected-netweaver-zer...
- https://www.theregister.com/2025/04/25/sap_netweaver_patch/
- https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324...
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-...