SAP Knowledge Base Article - Public

3694396 - Is SAP JAM impacted by React Server Components CVE-2025-55182 vulnerability?

Symptom

  • On December 3, 2025, the React Team publicly disclosed a critical security vulnerability affecting React Server Components (RSC) and related packages.
  • The vulnerability allows for unauthenticated remote code execution (RCE) via maliciously crafted HTTP requests.
  • Is SAP JAM is affected by CVE-2025-55182?

Environment

SAP Jam Collaboration

Resolution

SAP Security Engineering Team confirmed that SAP JAM is not impacted by CVE-2025-55182 as it does not utilize the vulnerable packages associated with React Server Components.

    See Also

    Keywords

    cve-2025-55182, sap jam, react server components, react client, vulnerability analysis, security risk, third-party software vulnerabilities, react packages, impact assessment, sap cloud identity services, DWS-19955, DWS-19954, DWS-19953 , KBA , LOD-SF-JAM-ADM , Administrator Access Request , Problem

    Product

    SAP Jam Collaboration all versions