{"cveID":"CVE-2025-31324","vendorProject":"SAP","product":"NetWeaver","vulnerabilityName":"SAP NetWeaver Unrestricted File Upload Vulnerability","dateAdded":"2025-04-29","shortDescription":"SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries.","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","dueDate":"2025-05-20","knownRansomwareCampaignUse":"Known","notes":"https://me.sap.com/notes/3594142 ; https://nvd.nist.gov/vuln/detail/CVE-2025-31324","cwes":["CWE-434"],"year":2025,"state":"mapped","stale_reasons":[],"mappings":[{"domain":"enterprise","cve":"CVE-2025-31324","technique":"T1055","technique_name_at_mapping":"Process Injection","mapping_type":"exploitation_technique","capability_group":"unrestricted_upload","comments":"Attackers have exploited this SAP vulnerability to achieve remote code execution on the target system by sending malicious ZIP files to specific server endpoints. This can be done either through use of a single command or by uploading a web shell.","references":["https://onapsis.com/blog/cve-2025-31324-exploit-update-attacker-analysis/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2025-31324","technique":"T1505.003","technique_name_at_mapping":"Web Shell","mapping_type":"exploitation_technique","capability_group":"unrestricted_upload","comments":"Attackers have exploited this SAP vulnerability to achieve remote code execution on the target system by sending malicious ZIP files to specific server endpoints. This can be done either through use of a single command or by uploading a web shell.","references":["https://onapsis.com/blog/cve-2025-31324-exploit-update-attacker-analysis/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2025-31324","technique":"T1059","technique_name_at_mapping":"Command and Scripting Interpreter","mapping_type":"primary_impact","capability_group":"unrestricted_upload","comments":"Attackers have exploited this SAP vulnerability to achieve remote code execution on the target system by sending malicious ZIP files to specific server endpoints. This can be done either through use of a single command or by uploading a web shell.","references":["https://onapsis.com/blog/cve-2025-31324-exploit-update-attacker-analysis/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"},{"domain":"enterprise","cve":"CVE-2025-31324","technique":"T1602","technique_name_at_mapping":"Data from Configuration Repository","mapping_type":"secondary_impact","capability_group":"unrestricted_upload","comments":"Attackers have exploited this SAP vulnerability to achieve remote code execution on the target system by sending malicious ZIP files to specific server endpoints. This can be done either through use of a single command or by uploading a web shell.","references":["https://onapsis.com/blog/cve-2025-31324-exploit-update-attacker-analysis/"],"status":"complete","source_file":"kev-07.28.2025_attack-16.1-enterprise.json","attack_version":"16.1","kev_snapshot":"07/28/2025"}],"techniques":[{"id":"T1055","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Process Injection","name_at_mapping":"Process Injection","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":37,"has_detection_strategy":true},{"id":"T1059","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Command and Scripting Interpreter","name_at_mapping":"Command and Scripting Interpreter","renamed":false,"revoked_by":null,"mapping_types":["primary_impact"],"sigma_rule_count":95,"has_detection_strategy":true},{"id":"T1505.003","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Web Shell","name_at_mapping":"Web Shell","renamed":false,"revoked_by":null,"mapping_types":["exploitation_technique"],"sigma_rule_count":35,"has_detection_strategy":true},{"id":"T1602","domains":["enterprise"],"in_current_bundle":true,"live":true,"name_now":"Data from Configuration Repository","name_at_mapping":"Data from Configuration Repository","renamed":false,"revoked_by":null,"mapping_types":["secondary_impact"],"sigma_rule_count":0,"has_detection_strategy":true}],"mapping_types":["exploitation_technique","primary_impact","secondary_impact"],"has_exploitation_technique":true,"mapping_attack_versions":["16.1"],"mapping_domains":["enterprise"],"sigma_coverage":"partial","sigma_rules_tagged_cve":["5b304bcb-ac33-49d0-87af-fa1b3ca94333","5b91409c-cb18-4ab6-ac75-c5759f998409","639b893f-f93a-4e53-a7c8-f08cf73fe7f7","69dea60b-2deb-4c9e-a685-ad542f4367f9","86a7c91f-98c3-4f14-a58d-d989421e1234","94e12f41-6cb3-45c5-97b1-c783a7bf2e72"],"added_after_mapping_snapshot":false,"_source":"kevmap","_built":"2026-08-24 19:45 UTC","_attack_version":"19.2"}