CVE-2025-30009
13.05.2025, 01:15
he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to execute malicious script in the victims browser. This vulnerability has low impact on confidentiality and integrity within the scope of that victims browser, with no effect on availability of the application
Awaiting analysis
This vulnerability is currently awaiting analysis.