CVE-2025-31324: SAP NetWeaver Visual Composer Metadata Uploader - Deserialization
HoneyLabs honeypots recorded 19 probes matching CVE-2025-31324 from 19 distinct source IP addresses in the last 7 days. Severity is rated critical.
This CVE is on CISA's Known Exploited Vulnerabilities list.
Request paths that identify it
- /developmentserver/metadatauploader
Addresses probing it
| Source IP | Probes | Network | Country |
|---|---|---|---|
| 52.248.41.236 | 1 | Microsoft Corporation | United States |
| 20.106.59.191 | 1 | Microsoft Corporation | United States |
| 52.248.42.67 | 1 | Microsoft Corporation | United States |
| 20.150.197.197 | 1 | Microsoft Corporation | United States |
| 4.150.202.179 | 1 | Microsoft Corporation | United States |
| 172.169.234.210 | 1 | Microsoft Corporation | United States |
| 20.83.45.83 | 1 | Microsoft Corporation | United States |
| 20.150.211.231 | 1 | Microsoft Corporation | United States |
Networks it comes from
| ASN | Organisation | Probes | Source IPs |
|---|---|---|---|
| AS8075 | Microsoft Corporation | 19 | 19 |
Captured requests
- /developmentserver/metadatauploader
HTTP client fingerprints (JA4H)
- ge11nn0400_88d30a62b7ad
CVE report
CVE report
Open a specific CVE from the CVE tracker.