CVE-2025-25243
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
11/02/2025
Last modified:
18/02/2025
Description
SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arbitrary file over the network without any user interaction. This can reveal highly sensitive information with no impact to integrity or availability.
Impact
Base Score 3.x
8.60
Severity 3.x
HIGH