SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
History

Tue, 29 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sat, 26 Apr 2025 01:45:00 +0000


Thu, 24 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 24 Apr 2025 17:00:00 +0000

Type Values Removed Values Added
Description SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
Title Missing Authorization check in SAP NetWeaver (Visual Composer development server)
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-04-24T16:50:27.706Z

Updated: 2025-04-30T03:56:20.842Z

Reserved: 2025-03-27T23:02:06.906Z

Link: CVE-2025-31324

cve-icon Vulnrichment

Updated: 2025-04-26T00:25:00.610Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-24T17:15:35.913

Modified: 2025-04-30T01:00:02.383

Link: CVE-2025-31324

cve-icon Redhat

No data.