CVE-2025-25243

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Feb 11, 2025
Updated: Feb 18, 2025
CWE ID 22

Summary

CVE-2025-25243 is a vulnerability affecting SAP Supplier Relationship Management (Master Data Management Catalog). An attacker can exploit this issue by accessing a publicly available servlet and download an arbitrary file over the network without any authentication or user interaction. The impact of this vulnerability is the potential disclosure of highly sensitive information, with no reported impact on system integrity or availability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • SAP Supplier Relationship Management

Affected Vendors

  • SAP SE