Due to directory traversal vulnerability, an authorized attacker could gain access to some critical information by using RFC enabled function module. Upon successful exploitation, they could read files from any managed system connected to SAP Solution Manager, leading to high impact on confidentiality. There is no impact on integrity or availability.
History

Tue, 08 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Apr 2025 07:30:00 +0000

Type Values Removed Values Added
Description Due to directory traversal vulnerability, an authorized attacker could gain access to some critical information by using RFC enabled function module. Upon successful exploitation, they could read files from any managed system connected to SAP Solution Manager, leading to high impact on confidentiality. There is no impact on integrity or availability.
Title Directory Traversal vulnerability in SAP NetWeaver and ABAP Platform (Service Data Collection)
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2025-04-08T14:50:32.851Z

Reserved: 2025-02-25T09:29:51.243Z

Link: CVE-2025-27428

cve-icon Vulnrichment

Updated: 2025-04-08T13:21:29.874Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-08T08:15:16.230

Modified: 2025-04-08T18:13:53.347

Link: CVE-2025-27428

cve-icon Redhat

No data.