CRITICAL🚩 CISA KEV⚡ EXPLOIT✓ PATCH🇵🇱 Wersja polska

CVE-2025-42999

CVSS 9.1v3.1pub. 2025-05-13upd. 2026-08-11

SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.

🤖 AI Analysis
How it works

The vulnerability (CWE-502 — deserialization of untrusted data) consists of the fact that the metadata transmission mechanism in Visual Composer does not sufficiently verify uploaded data before deserialization. A privileged user can upload a specially crafted file or data that will be executed by the application as code during the deserialization process. This leads to the execution of untrusted code on the SAP NetWeaver application server side.

Impact

An attacker can gain full access to sensitive data (confidentiality breach), modify or delete system data (integrity breach), and cause system unavailability (availability breach), including potential takeover of the entire host system.

Mitigation & patch

Patches available from the vendor must be applied immediately in accordance with SAP Note 3604119 and recommendations published as part of the SAP Security Patch Day. Due to active exploitation of the vulnerability, patch deployment should be treated as a priority.

Who is affected

SAP NetWeaver with the Visual Composer Metadata Uploader component — specific versions indicated in vendor references (SAP Note 3604119).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Sap Netweaver

    APP
    Sap
    7.5

CISA KEV — detailsi

Vendori
SAP
Producti
NetWeaver
Added to KEVi
May 15, 2025
Remediation deadline (US Federal)i
June 5, 2025(overdue)
Ransomwarei
Active ransomware campaigns exploit this vulnerability
Required action (CISA)i

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CISA descriptioni

SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content.

🔴
IMMEDIATE ACTION
Actively exploited in the wild (CISA KEV). Patch immediately.
☠️WYKORZYSTYWANE W RANSOMWARECISA DEADLINE: 5 czerwca 2025
Tags
Deserialization
CWE
References

Related vulnerabilities

CVE-2025-31324CRITICAL10.0⚠ KEVPL ✓same product

SAP NetWeaver: nieautoryzowany upload plików wykonywalnych w Visual Composer

CVE-2021-38163CRITICAL9.9⚠ KEVPL ✓same product

SAP NetWeaver Visual Composer — RCE przez path traversal przy uploadzie pliku

CVE-2023-36922CRITICAL9.1PL ✓same product

Command injection w SAP ECC i S/4HANA — komponent IS-OIL

CVE-2020-6203CRITICAL9.1PL ✓same product

Path Traversal w SAP NetWeaver UDDI Server (Services Registry)

CVE-2011-1517CRITICAL9.8PL ✓same product

SAP NetWeaver 7.0 — RCE i DoS przez błąd w funkcji DiagTraceHex()