CISA Known Exploited Vulnerability (KEV)
SAP NetWeaver Deserialization Vulnerability
May 15, 2025
June 5, 2025
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Description
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.
References
Weakness Enumeration
CWE-ID | CWE Name |
---|---|
CWE-502 |
Deserialization of Untrusted Data |