Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-31324

Опубликовано: 24 апр. 2025
Источник: nvd
CVSS3: 10
CVSS3: 9.8
EPSS Средний

Описание

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:sap:netweaver:7.50:*:*:*:*:*:*:*

EPSS

Процентиль: 96%
0.27874
Средний

10 Critical

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 10
github
10 месяцев назад

SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.

CVSS3: 10
fstec
10 месяцев назад

Уязвимость функции MetadataUploader инструмента Visual Composer программной интеграционной платформы SAP NetWeaver, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 96%
0.27874
Средний

10 Critical

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-434