CVE-2025-25243: SAP SE SAP Supplier Relationship Management Master Data Management Catalog

High severity, CVSS 8.6. EPSS: 0.7% chance of exploitation in the next 30 days.

SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arbitrary file over the network without any user interaction. This can reveal highly sensitive information with no impact to integrity or availability.

Affected products

  • SAP SE SAP Supplier Relationship Management Master Data Management Catalog

Published 2025-02-11. Last modified 2026-06-17.