Junglewise Threat Intelligence

CVE-2025-42999: SAP NetWeaver Deserialization Vulnerability

CVE-2025-42999 · Severity: critical · CVSS 9.1 · Exploited in the wild · Published 2025-05-15

Technologies: SAP NetWeaver. Vendors: SAP SE, SAP.

Executive brief

SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability (CWE-502). A privileged attacker can upload malicious content that, when deserialized, allows for the complete compromise of the host system's confidentiality, integrity, and availability.

Affected products

  • SAP SE NetWeaver Visual Composer Metadata Uploader 7.5

Timeline

  • 2025-05-12: disclosed: Initial disclosure by SAP SE
  • 2025-05-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2025-05-15: exploited: Reported as exploited in the wild

Related threats