# SAP NetWeaver中的授权检查缺失(视觉开发服务器)
## 漏洞概述
SAP NetWeaver Visual Composer Metadata Uploader由于缺乏适当的授权保护,允许未认证的攻击者上传潜在的恶意可执行二进制文件,从而严重危害目标主机系统。
## 影响版本
未指定具体版本
## 漏洞细节
SAP NetWeaver Visual Composer Metadata Uploader未实施适当的授权保护机制,导致任何未认证的用户均可上传恶意二进制文件至系统。
## 影响
此漏洞可能严重影响系统的保密性、完整性和可用性。
# | POC 描述 | 源链接 | 神龙链接 |
---|---|---|---|
1 | SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries that could severely harm the host system. This could significantly affect the confidentiality, integrity, and availability of the targeted system. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2025/CVE-2025-31324.yaml | POC详情 |
标题: SAP for Me: Sign In -- 🔗来源链接
标签: