CVE-2025-42999: SAP NetWeaver Deserialization Vulnerability
SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content.
Other sources
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Follow applicable BOD 22-01 guidance for cloud services.
- Compensating control
Discontinue use of the product (SAP NetWeaver / SAP NetWeaver Visual Composer, including the Visual Composer Metadata Uploader) if mitigations are unavailable.
Event History
Frequently Asked Questions
What is the severity of CVE-2025-42999?
CVE-2025-42999 is considered a critical vulnerability due to its potential to compromise confidentiality, integrity, and availability.
How do I fix CVE-2025-42999?
To fix CVE-2025-42999, ensure that you apply the appropriate patches provided by SAP for the NetWeaver Visual Composer.
What causes CVE-2025-42999?
CVE-2025-42999 is caused by the ability for a privileged user to upload untrusted or malicious content that can be exploited upon deserialization.
Who is affected by CVE-2025-42999?
CVE-2025-42999 affects users of SAP NetWeaver Visual Composer who have the ability to upload content.
What are the potential impacts of CVE-2025-42999?
The potential impacts of CVE-2025-42999 include unauthorized access to sensitive data and disruption of system operations.