CVE-2025-30009

he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to execute malicious script in the victim�s browser. This vulnerability has low impact on confidentiality and integrity within the scope of that victim�s browser, with no effect on availability of the application
Configurations

No configuration.

History

13 May 2025, 19:35

Type Values Removed Values Added
Summary
  • (es) Live Auction Cockpit de SAP Supplier Relationship Management (SRM) utiliza un componente de applet de Java obsoleto dentro de los paquetes SRM afectados, lo que permite a un atacante no autenticado ejecutar un script malicioso en el navegador de la víctima. Esta vulnerabilidad tiene un impacto mínimo en la confidencialidad e integridad del navegador de la víctima, sin afectar la disponibilidad de la aplicación.

13 May 2025, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-13 01:15

Updated : 2025-05-13 19:35


NVD link : CVE-2025-30009

Mitre link : CVE-2025-30009

CVE.ORG link : CVE-2025-30009


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')