CVE-2025-31324: SAP NetWeaver Visual Composer Metadata Uploader - Deserialization
HoneyLabs honeypots recorded 16 probes matching CVE-2025-31324 from 16 distinct source IP addresses in the last 7 days. Severity is rated critical.
This CVE is on CISA's Known Exploited Vulnerabilities list.
Request paths that identify it
- /developmentserver/metadatauploader
Addresses probing it
| Source IP | Probes | Network | Country |
|---|---|---|---|
| 4.148.240.180 | 1 | Microsoft Corporation | United States |
| 9.234.42.9 | 1 | Microsoft Corporation | United States |
| 172.174.201.58 | 1 | Microsoft Corporation | United States |
| 172.180.64.95 | 1 | Microsoft Corporation | United States |
| 40.124.114.163 | 1 | Microsoft Corporation | United States |
| 20.64.98.41 | 1 | Microsoft Corporation | United States |
| 40.80.203.4 | 1 | Microsoft Corporation | United States |
| 20.29.43.153 | 1 | Microsoft Corporation | United States |
Networks it comes from
| ASN | Organisation | Probes | Source IPs |
|---|---|---|---|
| AS8075 | Microsoft Corporation | 16 | 16 |
Captured requests
- /developmentserver/metadatauploader
HTTP client fingerprints (JA4H)
- ge11nn0400_88d30a62b7ad
CVE report
CVE report
Open a specific CVE from the CVE tracker.