CVE-2025-30010: Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to craft a malicious link, which when clicked by a victim, redirects the browser to a malicious site. On successful exploitation, the attacker could cause low impact on confidentiality and integrity with no impact on the availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30010?
CVE-2025-30010 is considered a high severity vulnerability due to its potential for exploitation by unauthenticated attackers.
How do I fix CVE-2025-30010?
To fix CVE-2025-30010, update to the latest version of SAP Supplier Relationship Management as per SAP's security advisories.
What types of attacks can CVE-2025-30010 facilitate?
CVE-2025-30010 can facilitate unauthorized access and phishing attacks through malicious link redirections.
Which version of SAP Supplier Relationship Management is affected by CVE-2025-30010?
CVE-2025-30010 affects all versions of SAP Supplier Relationship Management that utilize the vulnerable java applet component.
Is user interaction required to exploit CVE-2025-30010?
Yes, user interaction is required as the victim must click the malicious link for the attack to be successful.