Under certain conditions, an SSRF vulnerability in SAP CRM and SAP S/4HANA (Interaction Center) allows an attacker with low privileges to access restricted information. This flaw enables the attacker to send requests to internal network resources, thereby compromising the application's confidentiality. There is no impact on integrity or availability
History

Tue, 11 Mar 2025 02:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Mar 2025 01:00:00 +0000

Type Values Removed Values Added
Description Under certain conditions, an SSRF vulnerability in SAP CRM and SAP S/4HANA (Interaction Center) allows an attacker with low privileges to access restricted information. This flaw enables the attacker to send requests to internal network resources, thereby compromising the application's confidentiality. There is no impact on integrity or availability
Title Server Side Request Forgery (SSRF) in SAP CRM and SAP S/4 HANA (Interaction Center)
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 3.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2025-03-11T00:37:24.590Z

Updated: 2025-03-11T02:06:54.297Z

Reserved: 2025-02-25T09:29:51.244Z

Link: CVE-2025-27430

cve-icon Vulnrichment

Updated: 2025-03-11T02:06:50.763Z

cve-icon NVD

Status : Received

Published: 2025-03-11T01:15:36.157

Modified: 2025-03-11T01:15:36.157

Link: CVE-2025-27430

cve-icon Redhat

No data.