← Vulnerability feed

Vulnerability record · CVE-2025-42999 · published 13 May 2025

CVE-2025-42999: SAP NetWeaver Visual Composer Metadata Uploader deserialization flaw

Sap · Netweaver

SAP NetWeaver Visual Composer Metadata Uploader deserializes untrusted content uploaded by a privileged user, allowing malicious payloads to execute on the host. The flaw is rated critical (CVSS 9.1) and affects confidentiality, integrity and availability of the system.

9.1 CVSS 3.1 Critical CISA KEV since 15 May 2025 Known ransomware use EPSS 14% · top 3.6% CWE-502 · Deserialization of untrusted data
9.1CVSS 3.1 base score
14%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
4References, 1 tagged exploit
11 Aug 2026Last modified by NVD

Description

SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.1, active KEV listing with known ransomware use and a near-term federal remediation deadline make this an urgent patching priority.

What it is

SAP NetWeaver Visual Composer Metadata Uploader deserializes untrusted content uploaded by a privileged user, allowing malicious payloads to execute on the host. The flaw is rated critical (CVSS 9.1) and affects confidentiality, integrity and availability of the system.

Impact

An attacker with privileged access can execute arbitrary code on the SAP NetWeaver host, gaining full control over its confidentiality, integrity and availability.

Attack surface

Reached over the network through the Metadata Uploader upload function; the CVSS vector requires high privileges (PR:H) and no user interaction (UI:N).

Exploitation

CISA added it to KEV on 2025-05-15 with a 2025-06-05 remediation due date and flags known ransomware campaign use; EPSS 30-day probability is 0.13868 (96.3rd percentile).

What to do

  • Apply the SAP security note 3604119 patch or the vendor patch-day update immediately.
  • Restrict and audit privileged accounts that can access the Visual Composer Metadata Uploader.
  • If patching is not possible, disable or block the Metadata Uploader upload function per SAP guidance.
  • Follow BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are unavailable.

Detection

  • Monitor for unexpected uploads to the Visual Composer Metadata Uploader endpoint.
  • Alert on deserialization errors or unusual child processes spawned by SAP NetWeaver application servers.
  • Review privileged account activity and file writes in SAP NetWeaver directories for signs of payload staging.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2025-42999 to the Known Exploited Vulnerabilities catalog on 15 May 2025 as "SAP NetWeaver Deserialization Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 5 June 2025.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-42999 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-31324SAP NetWeaver Visual Composer Metadata Uploader unauthenticated file uploadThe SAP NetWeaver Visual Composer Metadata Uploader lacks proper authorization checks, letting an unauthenticated agent upload executable binaries to…KEVEPSS 99%analysed8.8CVE-2021-38163SAP NetWeaver Visual Composer unrestricted file upload leads to RCESAP NetWeaver Visual Composer 7.0 RT (versions 7.30, 7.31, 7.40, 7.50) allows an authenticated non-administrative user to upload a malicious file ove…KEVEPSS 36%analysed10.0CVE-2013-6822Sap netweaver vulnerabilityGRMGApp in SAP NetWeaver allows remote attackers to have unspecified impact and attack vectors, related to an XML External Entity (XXE) issue.EPSS 2.2%9.8CVE-2011-1517Sap netweaver vulnerabilitySAP NetWeaver 7.0 allows Remote Code Execution and Denial of Service caused by an error in the DiagTraceHex() function. By sending a specially-crafte…EPSS 4.2%9.8CVE-2013-1592Sap netweaver classic buffer overflow vulnerabilityA Buffer Overflow vulnerability exists in the Message Server service _MsJ2EE_AddStatistics() function when sending specially crafted SAP Message Serv…EPSS 24%9.8CVE-2015-7241Sap netweaver xml external entity (xxe) vulnerabilityXML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.EPSS 13%9.8CVE-2016-10311Sap netweaver memory buffer overflow vulnerabilityStack-based buffer overflow in SAP NetWeaver 7.0 through 7.5 allows remote attackers to cause a denial of service () by sending a crafted packet to t…EPSS 2.2%9.3CVE-2012-2611Sap netweaver improper input validation vulnerabilityThe DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispatcher in SAP NetWeaver 7.0 EH…EPSS 44%

Source: NIST National Vulnerability Database (record CVE-2025-42999), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.