Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)
Vulnerability Description
he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to execute malicious script in the victim�s browser. This vulnerability has low impact on confidentiality and integrity within the scope of that victim�s browser, with no effect on availability of the application
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-30009
Credits & Attribution
No credits recorded in the NVD database.
More from SAP_SE
View All →Affected Vendor
SAP_SE
View all reports →