CVE-2025-31324
KEV
🔴 Łataj teraz
Brak odpowiednich uprawnień w SAP NetWeaver umożliwia nieautoryzowane przesyłanie złośliwych plików.
CVSS
10.0
EPSS
99.5%
Exploit
weaponized
Vendor
sap
Opis źródłowy (NVD)
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 10.0 |
| CISA KEV (aktywnie wykorzystywane) | Tak |
| FIRST EPSS (prawdopodobieństwo exploita) | 99.5% |
| Opublikowano (NVD) | 2025-04-24 17:15:35 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-04 05:16:34 UTC |
Referencje
- https://me.sap.com/notes/3594142 (cna@sap.com) [Permissions Required]
- https://url.sap/sapsecuritypatchday (cna@sap.com) [Vendor Advisory]
- https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/ (af854a3a-2127-422b-91ae-364da2661108) [Third Party Advisory]
- https://www.bleepingcomputer.com/news/security/sap-fixes-suspected-netweaver-zero-day-exploited-in-attacks/ (af854a3a-2127-422b-91ae-364da2661108) [Press/Media Coverage]
- https://www.theregister.com/2025/04/25/sap_netweaver_patch/ (af854a3a-2127-422b-91ae-364da2661108) [Press/Media Coverage]
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-31324 (134c704f-9b21-4f2e-91b3-4a467353bcc0) [US Government Resource]