Symptom
- On December 3, 2025, the React Team publicly disclosed a critical security vulnerability affecting React Server Components (RSC) and related packages.
- The vulnerability allows for unauthenticated remote code execution (RCE) via maliciously crafted HTTP requests.
- Is SAP JAM is affected by CVE-2025-55182?
Environment
SAP Jam Collaboration
Resolution
SAP Security Engineering Team confirmed that SAP JAM is not impacted by CVE-2025-55182 as it does not utilize the vulnerable packages associated with React Server Components.
See Also
Keywords
cve-2025-55182, sap jam, react server components, react client, vulnerability analysis, security risk, third-party software vulnerabilities, react packages, impact assessment, sap cloud identity services, DWS-19955, DWS-19954, DWS-19953 , KBA , LOD-SF-JAM-ADM , Administrator Access Request , Problem
Product
SAP Jam Collaboration all versions
SAP Knowledge Base Article - Public