SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arbitrary file over the network without any user interaction. This can reveal highly sensitive information with no impact to integrity or availability.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Feb 2025 06:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 11 Feb 2025 01:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arbitrary file over the network without any user interaction. This can reveal highly sensitive information with no impact to integrity or availability. | |
Title | Path traversal vulnerability in SAP Supplier Relationship Management (Master Data Management Catalog) | |
Weaknesses | CWE-22 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: sap
Published: 2025-02-11T00:38:02.558Z
Updated: 2025-02-18T18:03:33.640Z
Reserved: 2025-02-04T23:28:33.502Z
Link: CVE-2025-25243

Updated: 2025-02-11T05:41:49.712Z

Status : Awaiting Analysis
Published: 2025-02-11T01:15:12.170
Modified: 2025-02-18T18:15:35.160
Link: CVE-2025-25243

No data.