April 29, 2025 · Applied Cybernetics Group
CVE-2025-31324 — SAP NetWeaver
known ransomware use
SAP NetWeaver Unrestricted File Upload Vulnerability
- Added to KEV
2025-04-29- Federal due date
2025-05-20- Vendor
- SAP
- Product
- NetWeaver
- EPSS
- 97.6th percentile (score 0.437, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Known
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2025-31324
CISA short description
SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.