Java Applet Vulnerability in SAP Supplier Relationship Management
CVE-2025-30010
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 13 May 2025
What is CVE-2025-30010?
The Live Auction Cockpit within SAP Supplier Relationship Management utilizes a deprecated Java applet component, which presents a security risk. This susceptibility allows unauthenticated attackers to create malicious links that, when clicked by users, redirect their browsers to harmful websites. Successful exploitation can compromise data confidentiality and integrity, while the availability of the application remains unaffected. Addressing this vulnerability is essential to ensure the security of the SRM environment.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP Supplier Relationship Management (Live Auction Cockpit) SRM_SERVER 7.14
References
CVSS V3.1
Timeline
Vulnerability published