Security Advisory

CVE-2025-25243

8.6
HIGH

Vulnerability Description

SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arbitrary file over the network without any user interaction. This can reveal highly sensitive information with no impact to integrity or availability.
Published Date February 11, 2025
Official Source NIST NVD Advisory