← back
CVE-2025-27430

Server Side Request Forgery (SSRF) in SAP CRM and SAP S/4 HANA (Interaction Center)

CVSS 3.5 LOWEPSS 0.2%CWE-918
Vexday Risk Score
8Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 3.5EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
11 Mar 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Under certain conditions, an SSRF vulnerability in SAP CRM and SAP S/4HANA (Interaction Center) allows an attacker with low privileges to access restricted information. This flaw enables the attacker to send requests to internal network resources, thereby compromising the application's confidentiality. There is no impact on integrity or availability
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →