CVE-2025-25243

SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arbitrary file over the network without any user interaction. This can reveal highly sensitive information with no impact to integrity or availability.
Configurations

No configuration.

History

18 Feb 2025, 18:15

Type Values Removed Values Added
Summary
  • (es) SAP Supplier Relationship Management (Master Data Management Catalog) permite que un atacante no autenticado utilice un servlet disponible públicamente para descargar un archivo arbitrario a través de la red sin interacción del usuario. Esto puede revelar información altamente confidencial sin afectar la integridad ni la disponibilidad.

11 Feb 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-11 01:15

Updated : 2025-02-18 18:15


NVD link : CVE-2025-25243

Mitre link : CVE-2025-25243

CVE.ORG link : CVE-2025-25243


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')