Executive brief
SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability (CWE-502). A privileged attacker can upload malicious content that, when deserialized, allows for the complete compromise of the host system's confidentiality, integrity, and availability.
Affected products
- SAP SE NetWeaver Visual Composer Metadata Uploader 7.5
Timeline
- 2025-05-12: disclosed: Initial disclosure by SAP SE
- 2025-05-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2025-05-15: exploited: Reported as exploited in the wild