SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.
The vulnerability (CWE-502 — deserialization of untrusted data) consists of the fact that the metadata transmission mechanism in Visual Composer does not sufficiently verify uploaded data before deserialization. A privileged user can upload a specially crafted file or data that will be executed by the application as code during the deserialization process. This leads to the execution of untrusted code on the SAP NetWeaver application server side.
An attacker can gain full access to sensitive data (confidentiality breach), modify or delete system data (integrity breach), and cause system unavailability (availability breach), including potential takeover of the entire host system.
Patches available from the vendor must be applied immediately in accordance with SAP Note 3604119 and recommendations published as part of the SAP Security Patch Day. Due to active exploitation of the vulnerability, patch deployment should be treated as a priority.
SAP NetWeaver with the Visual Composer Metadata Uploader component — specific versions indicated in vendor references (SAP Note 3604119).
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HSap Netweaver
APPSap7.5
CISA KEV — detailsi
- Vendori
- SAP
- Producti
- NetWeaver
- Added to KEVi
- May 15, 2025
- Remediation deadline (US Federal)i
- June 5, 2025(overdue)
- Ransomwarei
- Active ransomware campaigns exploit this vulnerability
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content.
Related vulnerabilities
SAP NetWeaver: nieautoryzowany upload plików wykonywalnych w Visual Composer
SAP NetWeaver Visual Composer — RCE przez path traversal przy uploadzie pliku
Command injection w SAP ECC i S/4HANA — komponent IS-OIL
Path Traversal w SAP NetWeaver UDDI Server (Services Registry)
SAP NetWeaver 7.0 — RCE i DoS przez błąd w funkcji DiagTraceHex()