EUVD-2025-11987
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 29 Apr 2025. Evidence sources: cisa_kev.
- ENISA score
- 10.0 · CVSS 3.1
- Advisory evidence
- 4 linked advisory records
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_ncscnl · NCSC-2025-0149Kwetsbaarheden verholpen in SAP producten
- csaf_ncscnl · NCSC-2025-0119Kwetsbaarheden verholpen in SAP-producten
