Description
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to craft a malicious link, which when clicked by a victim, redirects the browser to a malicious site. On successful exploitation, the attacker could cause low impact on confidentiality and integrity with no impact on the availability of the application.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14354 | The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to craft a malicious link, which when clicked by a victim, redirects the browser to a malicious site. On successful exploitation, the attacker could cause low impact on confidentiality and integrity with no impact on the availability of the application. |
References
History
Thu, 23 Oct 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap supplier Relationship Management |
|
| CPEs | cpe:2.3:a:sap:supplier_relationship_management:7.14:*:*:*:*:*:*:* | |
| Vendors & Products |
Sap
Sap supplier Relationship Management |
Tue, 13 May 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 May 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to craft a malicious link, which when clicked by a victim, redirects the browser to a malicious site. On successful exploitation, the attacker could cause low impact on confidentiality and integrity with no impact on the availability of the application. | |
| Title | Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit) | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-05-13T14:27:01.826Z
Reserved: 2025-03-13T18:03:35.488Z
Link: CVE-2025-30010
Updated: 2025-05-13T14:26:08.788Z
Status : Analyzed
Published: 2025-05-13T01:15:47.557
Modified: 2025-10-23T16:57:58.967
Link: CVE-2025-30010
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD