Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-14355 | he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to execute malicious script in the victim�s browser. This vulnerability has low impact on confidentiality and integrity within the scope of that victim�s browser, with no effect on availability of the application |
Thu, 23 Oct 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sap
Sap supplier Relationship Management |
|
| CPEs | cpe:2.3:a:sap:supplier_relationship_management:7.14:*:*:*:*:*:*:* | |
| Vendors & Products |
Sap
Sap supplier Relationship Management |
Tue, 13 May 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 May 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to execute malicious script in the victim�s browser. This vulnerability has low impact on confidentiality and integrity within the scope of that victim�s browser, with no effect on availability of the application | |
| Title | Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit) | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-05-13T14:06:31.756Z
Reserved: 2025-03-13T18:03:35.488Z
Link: CVE-2025-30009
Updated: 2025-05-13T14:06:25.502Z
Status : Analyzed
Published: 2025-05-13T01:15:47.407
Modified: 2025-10-23T17:00:46.330
Link: CVE-2025-30009
No data.
OpenCVE Enrichment
No data.
EUVD