Unrestricted file upload in SAP NetWeaver (CVE-2025-31324) — executable binaries uploadable without authentication, on a product with eleven KEV entries
The SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload flaw allowing an unauthenticated agent to upload potentially malicious executable binaries. CISA added it to the KEV catalog on 2025-04-29 with a due date of 2025-05-20.
Key facts
- CVE IDCVE-2025-31324
- Affected (vendor / product)SAP NetWeaver
- CWECWE-434
- ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
- Remediation due2025-05-20 (U.S. federal civilian agencies, BOD 22-01)
Key points
- The affected component is the SAP NetWeaver Visual Composer Metadata Uploader; CWE-434, unrestricted upload of file with dangerous type.
- An unauthenticated agent can upload potentially malicious executable binaries.
- Unrestricted signals that checks on extension and content and limits on the destination — the machinery keeping a placed file from executing — are not working.
- Added to KEV 2025-04-29 with a due date of 2025-05-20 — 21 days. Ransomware use is known.
- This site holds eleven NetWeaver records, four added on one day in November 2021; only the two from 2025 are ransomware-known.
- With no restriction on place or kind and no authentication required, an executable binary can be placed where the server runs it.
1Between being placed and being executed
Being able to upload a file is a function many systems provide. It turns dangerous when there is no limit on where files can go or what kinds are accepted. Place an executable binary somewhere the server executes, and what remains is waiting for the occasion to run.
What the word unrestricted signals is that the machinery meant to keep a placed file from executing — checks on extension and content, limits on the destination — is not working. Here the record adds that no authentication is required either.
2That it underpins core business operations
NetWeaver is widely used as the foundation beneath systems running core business operations. Accounting, purchasing, inventory and human resources sit on it, and if it stops, the business stops. A breach raises not only exfiltration of information but tampering with and halting of operational data.
It is also a class of system requiring coordination merely to take offline for an update, and a 21-day deadline reads as having factored that coordination in.
3Eleven records for one product, only two ransomware-known
The KEV records this site holds include eleven whose product is NetWeaver. Four were added on the same day in November 2021, three in June 2022, one in March 2025, and one each in April and May 2025. Of those eleven, only the two from 2025 are recorded as known to be used in ransomware campaigns, and both concern the Visual Composer Metadata Uploader. Even for one product, how it is exploited changes over time. Grouping the ledger by product name is what brings that change into view.
4Being able to place it, and it being executed
Being able to upload a file is a capability many systems have. It turns dangerous when there is no restriction on where files may be placed and of what kind.
NetWeaver is widely used as the foundation running an enterprise's core business systems. Accounting, purchasing, inventory and human resources ride on it, and if it stops the business stops. It is the kind of system whose downtime has to be arranged, and a remediation window of 21 days reads as allowing for that arrangement.
Why it matters
Foundations beneath core operations are hard to coordinate downtime for, so updates lag, while a breach reaches the whole business. Grouping records for one product chronologically shows which kinds of exploitation were confirmed when, and what to prioritize now looks different from what any single entry suggests.
FAQ
What is an unrestricted file upload?
Why does a core business system matter more?
Is one product recurring normal?
Sources (primary)
This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.
- CISA KEV Catalog (known exploited list)
- NVD (CVE details / CVSS)
- Vendor / reference advisory
- This product uses data from the NVD API but is not endorsed or certified by the NVD. KEV data is CC0 (public domain).