CVE-2025-30018 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request with a crafte…
High CVSS: 8.6

CVE-2025-30018

The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request with a crafted XML file which when parsed, enables the attacker to access sensitive files and data. This vulnerability has a high impact on the application's confidentiality, with no effect on integrity and availability of the application.
Vendor
Sap
Product
Supplier Relationship Management
CWE
CWE-611
Yayın Tarihi
2025-05-13 01:15:47
Güncelleme
2025-10-23 16:43:25
Source Identifier
cna@sap.com
KEV Date Added
-

Kategoriler

Referanslar