CVE-2025-25243: Path traversal vulnerability in SAP Supplier Relationship Management (Master Data Management Catalog)
SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arbitrary file over the network without any user interaction. This can reveal highly sensitive information with no impact to integrity or availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-25243?
CVE-2025-25243 is classified as a high severity vulnerability due to its potential to expose sensitive data without user interaction.
How do I fix CVE-2025-25243?
To fix CVE-2025-25243, apply the latest security patches provided by SAP for the Supplier Relationship Management software.
Who is affected by CVE-2025-25243?
CVE-2025-25243 affects users of SAP Supplier Relationship Management, specifically those utilizing the Master Data Management Catalog functionality.
What kind of information can CVE-2025-25243 expose?
CVE-2025-25243 can expose highly sensitive information from the server due to the arbitrary file download capability.
Can CVE-2025-25243 be exploited remotely?
Yes, CVE-2025-25243 allows unauthenticated attackers to exploit the vulnerability remotely to download files.