CVE-2025-42999
KEV · ransomware Critical · CVSS 9.1- CVSS
- 9.1
- nvd
- EPSS
- —
- KEV
- Listed
- ransomware
- Class
- other
- CWE-502
Description
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.
References
Status: profiled · ingested 2026-08-11T06:00:50.000Z