CVE-2025-42999

Source
https://cve.org/CVERecord?id=CVE-2025-42999
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-42999.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-42999
Published
2025-05-13T01:15:48.440Z
Modified
2026-03-13T03:10:48.978568Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.

References

Affected packages

Git /

Affected ranges

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-42999.json"
unresolved_ranges
[
    {
        "events": [
            {
                "introduced": "0"
            },
            {
                "last_affected": "7.5"
            }
        ]
    }
]