CVE-2025-25243

SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arbitrary file over the network without any user interaction. This can reveal highly sensitive information with no impact to integrity or availability.
Configurations

No configuration.

History

No history.

Information

Published : 2025-02-11 01:15

Updated : 2025-02-18 18:15


NVD link : CVE-2025-25243

Mitre link : CVE-2025-25243

CVE.ORG link : CVE-2025-25243


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')