SAP ERP BW Business Content is vulnerable to OS Command Injection through certain function modules. These function modules, when executed with elevated privileges, improperly handle user input, allowing attacker to inject arbitrary OS commands. This vulnerability allows the execution of unintended commands on the underlying system, posing a significant security risk to the confidentiality, integrity and availability of the application.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Apr 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 08 Apr 2025 07:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | SAP ERP BW Business Content is vulnerable to OS Command Injection through certain function modules. These function modules, when executed with elevated privileges, improperly handle user input, allowing attacker to inject arbitrary OS commands. This vulnerability allows the execution of unintended commands on the underlying system, posing a significant security risk to the confidentiality, integrity and availability of the application. | |
Title | Code Injection vulnerability in SAP ERP BW Business Content | |
Weaknesses | CWE-94 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-04-10T03:55:32.003Z
Reserved: 2025-03-13T18:03:35.488Z
Link: CVE-2025-30013

Updated: 2025-04-08T13:27:21.392Z

Status : Awaiting Analysis
Published: 2025-04-08T08:15:17.023
Modified: 2025-04-08T18:13:53.347
Link: CVE-2025-30013

No data.