CVE-2025-30012: Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which allows an unauthenticated attacker to send malicious payload request in a specific encoding format. The servlet will then decode this malicious request which will result in deserialization of data in the application leading to execution of arbitrary OS command on target as SAP Administrator. This vulnerability has High impact on confidentiality, integrity, and availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-30012?
CVE-2025-30012 has a high severity rating due to the potential for authenticated attackers with high privileges to exploit the vulnerability.
How do I fix CVE-2025-30012?
To fix CVE-2025-30012, it is recommended to upgrade to the latest version of SAP Supplier Relationship Management that addresses this vulnerability.
What does CVE-2025-30012 affect?
CVE-2025-30012 affects the Live Auction Cockpit component within SAP Supplier Relationship Management.
Can CVE-2025-30012 be exploited remotely?
CVE-2025-30012 cannot be exploited remotely as it requires authentication and high privileges.
What is the cause of CVE-2025-30012?
CVE-2025-30012 is caused by the use of a deprecated Java applet component that accepts binary Java objects in a specific encoding format.