Vulnerability record · CVE-2025-42999 · published 13 May 2025
CVE-2025-42999: SAP NetWeaver Visual Composer Metadata Uploader deserialization flaw
Sap · Netweaver
SAP NetWeaver Visual Composer Metadata Uploader deserializes untrusted content uploaded by a privileged user, allowing malicious payloads to execute on the host. The flaw is rated critical (CVSS 9.1) and affects confidentiality, integrity and availability of the system.
Description
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.1, active KEV listing with known ransomware use and a near-term federal remediation deadline make this an urgent patching priority.
What it is
SAP NetWeaver Visual Composer Metadata Uploader deserializes untrusted content uploaded by a privileged user, allowing malicious payloads to execute on the host. The flaw is rated critical (CVSS 9.1) and affects confidentiality, integrity and availability of the system.
Impact
An attacker with privileged access can execute arbitrary code on the SAP NetWeaver host, gaining full control over its confidentiality, integrity and availability.
Attack surface
Reached over the network through the Metadata Uploader upload function; the CVSS vector requires high privileges (PR:H) and no user interaction (UI:N).
Exploitation
CISA added it to KEV on 2025-05-15 with a 2025-06-05 remediation due date and flags known ransomware campaign use; EPSS 30-day probability is 0.13868 (96.3rd percentile).
What to do
- Apply the SAP security note 3604119 patch or the vendor patch-day update immediately.
- Restrict and audit privileged accounts that can access the Visual Composer Metadata Uploader.
- If patching is not possible, disable or block the Metadata Uploader upload function per SAP guidance.
- Follow BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are unavailable.
Detection
- Monitor for unexpected uploads to the Visual Composer Metadata Uploader endpoint.
- Alert on deserialization errors or unusual child processes spawned by SAP NetWeaver application servers.
- Review privileged account activity and file writes in SAP NetWeaver directories for signs of payload staging.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-42999 to the Known Exploited Vulnerabilities catalog on 15 May 2025 as "SAP NetWeaver Deserialization Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 5 June 2025.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://me.sap.com/notes/3604119 | Permissions Required |
| https://url.sap/sapsecuritypatchday | Vendor Advisory |
| https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324/ | ExploitThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-42999 | US Government Resource |
Track CVE-2025-42999 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-42999), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.