The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to craft a malicious link, which when clicked by a victim, redirects the browser to a malicious site. On successful exploitation, the attacker could cause low impact on confidentiality and integrity with no impact on the availability of the application.
Metrics
Affected Vendors & Products
References
History
Tue, 13 May 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 13 May 2025 00:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to craft a malicious link, which when clicked by a victim, redirects the browser to a malicious site. On successful exploitation, the attacker could cause low impact on confidentiality and integrity with no impact on the availability of the application. | |
Title | Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit) | |
Weaknesses | CWE-601 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: sap
Published: 2025-05-13T00:13:04.776Z
Updated: 2025-05-13T14:27:01.826Z
Reserved: 2025-03-13T18:03:35.488Z
Link: CVE-2025-30010

Updated: 2025-05-13T14:26:08.788Z

Status : Awaiting Analysis
Published: 2025-05-13T01:15:47.557
Modified: 2025-05-13T19:35:25.503
Link: CVE-2025-30010

No data.