PT-2025-1038 · Microsoft · Purview

Published

2025-01-09

·

Updated

2025-03-24

·

CVE-2025-21385

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
A Server-Side Request Forgery (SSRF) issue exists in Microsoft Purview, allowing an authorized attacker to disclose information over a network. The affected software is Microsoft Purview, but the specific versions are not mentioned in the provided text. An exploit for this issue is available, with example code found at https://t.co/pjZlXNplRN. Further information can be found at https://t.co/zO5JzPHB8q, https://t.co/wkgoebgdM5, https://t.co/zMWGsauC2v, https://t.co/1uOrgMTikk, https://t.co/uLzNFNtlMA, and https://t.co/bfAapg51kw. #MicrosoftPurview #SSRF #ServerSideRequestForgery #Microsoft #Cybersecurity

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-00247
CVE-2025-21385

Affected Products

Purview