We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-42977

Directory Traversal vulnerability in SAP NetWeaver Visual Composer



Description

SAP NetWeaver Visual Composer contains a Directory Traversal vulnerability caused by insufficient validation of input paths provided by a high-privileged user. This allows an attacker to read or modify arbitrary files, resulting in a high impact on confidentiality and a low impact on integrity.

Reserved 2025-04-16 | Published 2025-06-10 | Updated 2025-06-10 | Assigner sap


HIGH: 7.6CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N

Problem types

CWE-22: Improper Limitation of a Pathname to a Restricted Directory

Product status

Default status
unaffected

VCBASE 7.50
affected

References

me.sap.com/notes/3610591

url.sap/sapsecuritypatchday

cve.org (CVE-2025-42977)

nvd.nist.gov (CVE-2025-42977)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-42977

Support options

Helpdesk Chat, Email, Knowledgebase