PT-2025-15371 · Sap · Sap Erp Bw Business Content

Published

2025-04-08

·

Updated

2025-04-08

·

CVE-2025-30013

CVSS v2.0

6.8

Medium

VectorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: SAP ERP BW Business Content (affected versions not specified)
Description: The issue is related to OS Command Injection through certain function modules. When these modules are executed with elevated privileges, they improperly handle user input, allowing an attacker to inject arbitrary OS commands. This poses a significant security risk to the confidentiality, integrity, and availability of the application.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2025-04844
CVE-2025-30013

Affected Products

Sap Erp Bw Business Content