CVE-2025-31324 – Executable file upload vulnerability in SAP NetWeaver Application Server
A critical vulnerability, CVE-2025-31324, has been identified in SAP NetWeaver Visual Composer, allowing unauthenticated remote code execution via the Metadata Uploader component. This flaw arises from improper authentication checks, enabling attackers to send crafted HTTP/HTTPS requests to upload malicious binaries. Successful exploitation can result in complete system compromise. The issue affects all SAP NetWeaver 7.xx versions. Users are strongly advised to apply the emergency patch released by SAP. The IONIX research team verified the vulnerability’s impact through exploit simulation, detailed in this post.
References: