CVE-2025-27428 Information
Apr 09, 2025
cve
Description
Due to directory traversal vulnerability an authorized attacker could gain access to some critical information by using RFC enabled function module. Upon successful exploitation they could read files from any managed system connected to SAP Solution Manager leading to high impact on confidentiality. There is no impact on integrity or availability.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Reference
https://me.sap.com/notes/3581811 https://url.sap/sapsecuritypatchday https://url.sap/sapsecuritypatchday
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
CHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
7.7
Share on: