Unauthorized Access Vulnerability in SAP Supplier Relationship Management
CVE-2025-30018
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 13 May 2025
What is CVE-2025-30018?
The Live Auction Cockpit functionality within SAP Supplier Relationship Management (SRM) is susceptible to an unauthorized access vulnerability. This flaw allows attackers without authentication to craft and submit application servlet requests containing specially designed XML files. When these files are parsed by the application, it can lead to unauthorized access, exposing sensitive files and data stored within the system. While this vulnerability can compromise the confidentiality of the application's data, it does not impact the integrity or availability of the application itself.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP Supplier Relationship Management (Live Auction Cockpit) SRM_SERVER 7.14
References
CVSS V3.1
Timeline
Vulnerability published