CVE-2025-31324

Source
https://cve.org/CVERecord?id=CVE-2025-31324
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-31324.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-31324
Published
2025-04-24T17:15:35.913Z
Modified
2026-03-14T12:42:59.485728Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-31324.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "7.50"
            }
        ]
    }
]