EUVD-2025-14349
SAP NetWeaver Visual Composer Metadata Uploader is vulnerable when a privileged user can upload untrusted or malicious content which, when deserialized, could potentially lead to a compromise of confidentiality, integrity, and availability of the host system.
- EUVD state
- Present in the current official mapping
- Known exploitation
- Recorded by ENISA since 15 May 2025. Evidence sources: cisa_kev.
- ENISA score
- 9.1 · CVSS 3.1
- Advisory evidence
- 2 linked advisory records
Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.
- csaf_ncscnl · NCSC-2025-0149Kwetsbaarheden verholpen in SAP producten
