CVE-2025-25243: SAP SE SAP Supplier Relationship Management Master Data Management Catalog
High severity, CVSS 8.6. EPSS: 0.7% chance of exploitation in the next 30 days.
SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arbitrary file over the network without any user interaction. This can reveal highly sensitive information with no impact to integrity or availability.
Affected products
- SAP SE SAP Supplier Relationship Management Master Data Management Catalog
Published 2025-02-11. Last modified 2026-06-17.