Unauthorized Access Vulnerability in SAP Supplier Relationship Management
CVE-2025-30018
8.6HIGH
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 13 May 2025
What is CVE-2025-30018?
The Live Auction Cockpit functionality within SAP Supplier Relationship Management (SRM) is susceptible to an unauthorized access vulnerability. This flaw allows attackers without authentication to craft and submit application servlet requests containing specially designed XML files. When these files are parsed by the application, it can lead to unauthorized access, exposing sensitive files and data stored within the system. While this vulnerability can compromise the confidentiality of the application's data, it does not impact the integrity or availability of the application itself.
Affected Version(s)
SAP Supplier Relationship Management (Live Auction Cockpit) SRM_SERVER 7.14
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published