CVE-2025-27430: Server Side Request Forgery (SSRF) in SAP CRM and SAP S/4 HANA (Interaction Center)
Under certain conditions, an SSRF vulnerability in SAP CRM and SAP S/4HANA (Interaction Center) allows an attacker with low privileges to access restricted information. This flaw enables the attacker to send requests to internal network resources, thereby compromising the application's confidentiality. There is no impact on integrity or availability
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27430?
CVE-2025-27430 is classified as a high severity vulnerability due to its potential to allow unauthorized access to restricted information.
How do I fix CVE-2025-27430?
To fix CVE-2025-27430, apply the latest security patches provided by SAP for the affected versions of SAP CRM and SAP S/4HANA.
What systems are affected by CVE-2025-27430?
CVE-2025-27430 affects SAP CRM and SAP S/4HANA (Interaction Center) under certain conditions.
What are the risks associated with CVE-2025-27430?
The risks associated with CVE-2025-27430 include potential data theft and unauthorized access to internal systems by low-privilege attackers.
Can CVE-2025-27430 be exploited remotely?
Yes, CVE-2025-27430 can be exploited remotely by leveraging the SSRF vulnerability to access internal network resources.