Directory Traversal Vulnerability in SAP NetWeaver Visual Composer
CVE-2025-42977

7.6HIGH

Key Information:

Vendor

SAP

Vendor
CVE Published:
10 June 2025

What is CVE-2025-42977?

SAP NetWeaver Visual Composer is susceptible to a Directory Traversal vulnerability arising from inadequate validation of input paths submitted by users with elevated privileges. This flaw enables attackers to potentially gain access to, or alter, arbitrary files on the server, which can severely compromise the confidentiality of sensitive information while also posing a risk to data integrity.

Affected Version(s)

SAP NetWeaver Visual Composer VCBASE 7.50

References

CVSS V3.1

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-42977 : Directory Traversal Vulnerability in SAP NetWeaver Visual Composer