Directory Traversal Vulnerability in SAP Capital Yield Tax Management
CVE-2025-30014

7.7HIGH

Key Information:

Vendor
SAP
Vendor
CVE Published:
8 April 2025

Summary

SAP Capital Yield Tax Management is susceptible to a directory traversal vulnerability due to inadequate path validation mechanisms. This flaw allows attackers with limited privileges to exploit the system and gain unauthorized access to files located in restricted directories, potentially compromising sensitive data. Although this impacts confidentiality, the integrity and availability of the system remain unaffected. Organizations utilizing this product should promptly assess their security posture and implement necessary measures to mitigate exposure. For more information, consult SAP's official resources and security notes.

Affected Version(s)

SAP Capital Yield Tax Management CYTERP 420_700

SAP Capital Yield Tax Management CYT 800

SAP Capital Yield Tax Management IBS 7.0

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.