Skip to content
COOEY

EXPOSURES › CVE-2025-42999

CVE-2025-42999

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2025-05-15 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2025-42999 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

SAP NetWeaver Visual Composer Metadata Uploader had an unpatched deserialization vulnerability exploited in the wild, impacting confidentiality, integrity, and availability.

SAP NetWeaver Visual Composer Metadata Uploader, affecting all versions, had a critical deserialization flaw that was actively exploited, leading to potential unauthorized access and system compromise.

Shame score — Active exploitation of a critical vulnerability in a widely-used product by an unauthorized party.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
SAP NS2 Cloud Intelligent Enterprise
SAP National Security Services Inc. (SAP NS2)
Authorized
SAP NS2 Secure Node with SuccessFactors Suite - DoD
SAP National Security Services Inc. (SAP NS2)
Authorized