First published: Tue Apr 08 2025(Updated: )
SAP ERP BW Business Content is vulnerable to OS Command Injection through certain function modules. These function modules, when executed with elevated privileges, improperly handle user input, allowing attacker to inject arbitrary OS commands. This vulnerability allows the execution of unintended commands on the underlying system, posing a significant security risk to the confidentiality, integrity and availability of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP ERP BW Business Content |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30013 has been classified as a critical vulnerability due to its potential for OS command injection which can lead to significant security breaches.
To mitigate CVE-2025-30013, ensure that the system is updated with the latest patches provided by SAP that address the vulnerable function modules.
CVE-2025-30013 specifically affects SAP ERP BW Business Content, particularly when function modules are executed with elevated privileges.
CVE-2025-30013 allows attackers to perform OS command injection attacks, enabling them to execute arbitrary commands on the operating system.
Implementing strict input validation and limiting the execution privileges of function modules can help safeguard against CVE-2025-30013.