SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://me.sap.com/notes/3604119 | permissions required |
https://url.sap/sapsecuritypatchday | not applicable |
https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/ | exploit third party advisory |