CVE-2025-25243 | Path traversal vulnerability in SAP Supplier Relationship Management (Master Data Management Catalog)
SAP Supplier Relationship Management (Master Data Management Catalog) allows an unauthenticated attacker to use a publicly available servlet to download an arbitrary file over the network without any user interaction. This can reveal highly sensitive information with no impact to integrity or availability.
Conclusion & alert: CVE-2025-25243 is rated Moderate Risk (50.9/100): CVSS High severity, with low exploitation likelihood (EPSS 0.26%).Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Exploit prediction scoring system (EPSS) score for CVE-2025-25243
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).