EXPOSURES › CVE-2025-42999
CVE-2025-42999
HIGH ⌖ ON CISA KEV · EXPLOITEDSAP NetWeaver Visual Composer Metadata Uploader had an unpatched deserialization vulnerability exploited in the wild, impacting confidentiality, integrity, and availability.
SAP NetWeaver Visual Composer Metadata Uploader, affecting all versions, had a critical deserialization flaw that was actively exploited, leading to potential unauthorized access and system compromise.
Shame score — Active exploitation of a critical vulnerability in a widely-used product by an unauthorized party.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content.
| PRODUCT | STATUS |
|---|---|
| SAP NS2 Cloud Intelligent Enterprise SAP National Security Services Inc. (SAP NS2) |
Authorized |
| SAP NS2 Secure Node with SuccessFactors Suite - DoD SAP National Security Services Inc. (SAP NS2) |
Authorized |