Due to directory traversal vulnerability, an authorized attacker could gain access to some critical information by using RFC enabled function module. Upon successful exploitation, they could read files from any managed system connected to SAP Solution Manager, leading to high impact on confidentiality. There is no impact on integrity or availability.
References
Configurations
No configuration.
History
08 Apr 2025, 18:13
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
08 Apr 2025, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-08 08:15
Updated : 2025-04-08 18:13
NVD link : CVE-2025-27428
Mitre link : CVE-2025-27428
CVE.ORG link : CVE-2025-27428
JSON object : View
Products Affected
No product.
CWE
CWE-862
Missing Authorization