LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-42999: SAP NetWeaver Deserialization Vulnerability

RBRecent Breaches Vulnerability Intelligence·May 15, 2025
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
Jun 5, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-42999 to its Known Exploited Vulnerabilities catalog on May 15, 2025, with a federal patch deadline of Jun 5, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host…

CVE-2025-42999 is a deserialization vulnerability in SAP NetWeaver, specifically involving the Visual Composer Metadata Uploader. It allows a privileged attacker to deserialize untrusted or malicious content, which can compromise the confidentiality, integrity, and availability of the host system. For IT and security teams running SAP environments, this matters because NetWeaver often sits at the core of enterprise business processes; successful abuse can give an attacker a foothold to disrupt operations or move laterally.

Public detail is limited to the CISA summary and the CWE classification. Confirm all version, patch, and configuration specifics against the vendor advisory before acting.

How it works

The weakness is CWE-502: deserialization of untrusted data. In this class of flaw, an application accepts serialized objects or metadata and reconstructs them in memory without sufficient validation. When the reconstructed content contains attacker-controlled code or object graphs, the runtime can execute unintended logic under the privileges of the process performing the deserialization.

According to the CISA summary, a privileged attacker targets the Visual Composer Metadata Uploader component of SAP NetWeaver. By supplying malicious content that the uploader then deserializes, the attacker can achieve compromise of the host system. Exact exploit mechanics, payload formats, or required authentication steps are not provided in the available facts; treat any public proof-of-concept claims with caution and verify against the official SAP advisory.

Am I affected? How to find it in your systems

SAP NetWeaver is typically deployed as the application server foundation for SAP ERP, CRM, and related business suites. It may run on-premises, in private clouds, or as part of managed SAP landscapes. Visual Composer is a development and modeling tool whose Metadata Uploader handles import of model definitions and related artifacts.

How to remediate

Patch first. Apply the vendor-supplied update or support package that addresses CVE-2025-42999 exactly as described in the official SAP security note or advisory. Follow SAP’s recommended deployment sequence for NetWeaver landscapes so that development and quality systems are validated before production.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls appropriate to a privileged deserialization vulnerability.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to full host compromise and subsequent data breaches. Known ransomware use of CVE-2025-42999 is not documented in the available facts. If you suspect exploitation, isolate the affected systems, preserve logs and memory images, and begin incident-response procedures. As a quick personal check, you can run a free exposure scan of your email address against known breach data sets to see whether credentials or personal information have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSAP · NetWeaver
WeaknessCWE-502
Added to CISA KEVMay 15, 2025
Federal patch deadlineJun 5, 2025
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities