vulnerability

SAP NetWeaver: CVE-2025-42999: Deserialization of Untrusted Data

Severity
8
CVSS
(AV:N/AC:L/Au:M/C:C/I:C/A:C)
Published
May 13, 2025
Added
Jul 17, 2025
Modified
Jul 17, 2025

Description

SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.

Solution

sap-netweaver-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.