CVE-2025-25243

SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arbitrary file over the network without any user interaction. This can reveal highly sensitive information with no impact to integrity or availability.
CVSS

No CVSS.

Configurations

No configuration.

History

11 Feb 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-11 01:15

Updated : 2025-02-18 18:15


NVD link : CVE-2025-25243

Mitre link : CVE-2025-25243


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')