SSRF Vulnerability in SAP CRM and S/4HANA Products by SAP
CVE-2025-27430
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 11 March 2025
What is CVE-2025-27430?
A Server-Side Request Forgery (SSRF) vulnerability exists in SAP CRM and SAP S/4HANA, specifically in the Interaction Center module. This issue allows an attacker with minimal privileges to make unauthorized requests to internal network resources, potentially leading to exposure of sensitive information. The flaw compromises the confidentiality of the application but does not affect its integrity or availability. It is crucial for organizations utilizing these systems to address this vulnerability promptly to safeguard their data.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP CRM and SAP S/4HANA (Interaction Center) S4CRM 100
SAP CRM and SAP S/4HANA (Interaction Center) 200
SAP CRM and SAP S/4HANA (Interaction Center) 204
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved