Record summary

CVE-2025-42999 has a selected CVSS score of 9.1 (critical); EIP currently links 1 repository PoC. CISA lists CVE-2025-42999 in KEV and reports its use in known ransomware campaigns.

Description

SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.

Description source: CVE List

Exploitation context

Known exploitation

CISA KEV
Listed · May 15, 2025 · CISA
VulnCheck KEV
Listed · Apr 27, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck
Ransomware use
Observed · CISA

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationActive
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated May 12, 2025 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CISAVersion data not supplied

SAP NetWeaver (Visual Composer development server)

Browse SAP_SE / SAP NetWeaver (Visual Composer development server)

Default status: unaffected

CVE ListVCFRAMEWORK 7.50affected

Proofs of concept

1

Repository PoCs

GitHubOnapsis/Onapsis-Mandiant-CVE-2025-31324-Vuln-Compromise-AssessmentRepository PoCby OnapsisStars: 9Not analyzed5 files

63.7 KiB · linked to 2 vulnerabilities

GitHub

PoC details

References

5