CVE-2025-30009: Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)
he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to execute malicious script in the victim�s browser. This vulnerability has low impact on confidentiality and integrity within the scope of that victim�s browser, with no effect on availability of the application
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30009?
CVE-2025-30009 is considered a low impact vulnerability that allows an attacker to execute malicious scripts in the victim's browser.
How do I fix CVE-2025-30009?
To fix CVE-2025-30009, it is advised to update to the latest version of SAP Supplier Relationship Management that does not include the deprecated java applet component.
What versions of SAP Supplier Relationship Management are affected by CVE-2025-30009?
All versions of SAP Supplier Relationship Management that include the deprecated java applet component are affected by CVE-2025-30009.
Who can exploit CVE-2025-30009?
CVE-2025-30009 can be exploited by unauthenticated attackers who can execute malicious scripts in the browser of a targeted victim.
What is the primary risk associated with CVE-2025-30009?
The primary risk associated with CVE-2025-30009 is the potential for execution of malicious scripts in the user's browser, which may lead to further security issues.