Skip to main content

NetWeaver vulnerabilities

2 published alerts for SAP NetWeaver.

Actively exploited (KEV)Ransomware

CVE-2025-42999

SAP NetWeaver Deserialization Vulnerability

SAP NetWeaver is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-42999). SAP NetWeaver Visual Composer Metadata Uploader contains a deserialization vulnerability that allows a privileged attacker to compromise the confidentiality, integrity, and availability of the host system by deserializing untrusted or malicious content. CISA remediation due date: 2025-06-05. If you need help checking exposure, call (864) 335-9223.

Actively exploited (KEV)Ransomware

CVE-2025-31324

SAP NetWeaver Unrestricted File Upload Vulnerability

SAP NetWeaver is listed in CISA's Known Exploited Vulnerabilities catalog (CVE-2025-31324). SAP NetWeaver Visual Composer Metadata Uploader contains an unrestricted file upload vulnerability that allows an unauthenticated agent to upload potentially malicious executable binaries. CISA remediation due date: 2025-05-20. If you need help checking exposure, call (864) 335-9223.