he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected SRM packages which allows an unauthenticated attacker to execute malicious script in the victim?s browser. This vulnerability has low impact on confidentiality and integrity within the scope of that victim?s browser, with no effect on availability of the application
References
Configurations
No configuration.
History
13 May 2025, 01:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-13 01:15
Updated : 2025-05-13 01:15
NVD link : CVE-2025-30009
Mitre link : CVE-2025-30009
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')