Exploited Known exploited (KEV) Ransomware use CVE-2025-31324

Unrestricted file upload in SAP NetWeaver (CVE-2025-31324) — executable binaries uploadable without authentication, on a product with eleven KEV entries

SAP NetWeaver Added to KEV Apr 29, 2025 Federal remediation due 2025-05-20

The SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload flaw allowing an unauthenticated agent to upload potentially malicious executable binaries. CISA added it to the KEV catalog on 2025-04-29 with a due date of 2025-05-20.

Key facts

  • CVE IDCVE-2025-31324
  • Affected (vendor / product)SAP NetWeaver
  • CWECWE-434
  • ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
  • Remediation due2025-05-20 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • The affected component is the SAP NetWeaver Visual Composer Metadata Uploader; CWE-434, unrestricted upload of file with dangerous type.
  • An unauthenticated agent can upload potentially malicious executable binaries.
  • Unrestricted signals that checks on extension and content and limits on the destination — the machinery keeping a placed file from executing — are not working.
  • Added to KEV 2025-04-29 with a due date of 2025-05-20 — 21 days. Ransomware use is known.
  • This site holds eleven NetWeaver records, four added on one day in November 2021; only the two from 2025 are ransomware-known.
  • With no restriction on place or kind and no authentication required, an executable binary can be placed where the server runs it.

1Between being placed and being executed

Being able to upload a file is a function many systems provide. It turns dangerous when there is no limit on where files can go or what kinds are accepted. Place an executable binary somewhere the server executes, and what remains is waiting for the occasion to run.

What the word unrestricted signals is that the machinery meant to keep a placed file from executing — checks on extension and content, limits on the destination — is not working. Here the record adds that no authentication is required either.

2That it underpins core business operations

NetWeaver is widely used as the foundation beneath systems running core business operations. Accounting, purchasing, inventory and human resources sit on it, and if it stops, the business stops. A breach raises not only exfiltration of information but tampering with and halting of operational data.

It is also a class of system requiring coordination merely to take offline for an update, and a 21-day deadline reads as having factored that coordination in.

3Eleven records for one product, only two ransomware-known

The KEV records this site holds include eleven whose product is NetWeaver. Four were added on the same day in November 2021, three in June 2022, one in March 2025, and one each in April and May 2025. Of those eleven, only the two from 2025 are recorded as known to be used in ransomware campaigns, and both concern the Visual Composer Metadata Uploader. Even for one product, how it is exploited changes over time. Grouping the ledger by product name is what brings that change into view.

4Being able to place it, and it being executed

Being able to upload a file is a capability many systems have. It turns dangerous when there is no restriction on where files may be placed and of what kind.

Being able to uploadBeing liable to execution
A capability many systems haveDangerous once place and kind are unrestricted
Receiving a file is not itself a problemAn executable binary can be placed where the server will run it
Checks stop it if they are workingExtension and content checks and destination limits are not working
Authentication narrows the entranceHere, the record states none is required

NetWeaver is widely used as the foundation running an enterprise's core business systems. Accounting, purchasing, inventory and human resources ride on it, and if it stops the business stops. It is the kind of system whose downtime has to be arranged, and a remediation window of 21 days reads as allowing for that arrangement.

Why it matters

Foundations beneath core operations are hard to coordinate downtime for, so updates lag, while a breach reaches the whole business. Grouping records for one product chronologically shows which kinds of exploitation were confirmed when, and what to prioritize now looks different from what any single entry suggests.

FAQ

What is an unrestricted file upload?
A state with no limit on where files may go or what kinds are accepted. Placing an executable binary somewhere the server executes opens a path to code execution.
Why does a core business system matter more?
Accounting, purchasing, inventory and human resources run on it, so if it stops the business stops. Beyond exfiltration, tampering with and halting operational data are at issue.
Is one product recurring normal?
This site holds eleven NetWeaver records. Only the two from 2025 are ransomware-known, so how a product is exploited changes over time.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Security#CISA#KEV#Core business systems#SAP
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.