Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-4094 | SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arbitrary file over the network without any user interaction. This can reveal highly sensitive information with no impact to integrity or availability. |
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 11 Feb 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Feb 2025 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arbitrary file over the network without any user interaction. This can reveal highly sensitive information with no impact to integrity or availability. | |
| Title | Path traversal vulnerability in SAP Supplier Relationship Management (Master Data Management Catalog) | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-02-18T18:03:33.640Z
Reserved: 2025-02-04T23:28:33.502Z
Link: CVE-2025-25243
Updated: 2025-02-11T05:41:49.712Z
Status : Deferred
Published: 2025-02-11T01:15:12.170
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-25243
No data.
OpenCVE Enrichment
No data.
EUVD