Description
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request with a crafted XML file which when parsed, enables the attacker to access sensitive files and data. This vulnerability has a high impact on the application's confidentiality, with no effect on integrity and availability of the application.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14337 | The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request with a crafted XML file which when parsed, enables the attacker to access sensitive files and data. This vulnerability has a high impact on the application's confidentiality, with no effect on integrity and availability of the application. |
References
History
Thu, 23 Oct 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap supplier Relationship Management |
|
| CPEs | cpe:2.3:a:sap:supplier_relationship_management:7.14:*:*:*:*:*:*:* | |
| Vendors & Products |
Sap
Sap supplier Relationship Management |
Tue, 13 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 May 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request with a crafted XML file which when parsed, enables the attacker to access sensitive files and data. This vulnerability has a high impact on the application's confidentiality, with no effect on integrity and availability of the application. | |
| Title | Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit) | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-05-13T14:12:04.345Z
Reserved: 2025-03-13T18:03:35.489Z
Link: CVE-2025-30018
Updated: 2025-05-13T14:11:58.912Z
Status : Analyzed
Published: 2025-05-13T01:15:47.980
Modified: 2025-10-23T16:43:25.360
Link: CVE-2025-30018
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD