PT-2025-20806 · Sap · Sap Srm

Published

2025-05-13

·

Updated

2025-10-23

·

CVE-2025-30010

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions SAP Supplier Relationship Management (SRM) (affected versions not specified)
Description The issue concerns the use of a deprecated java applet component within the Live Auction Cockpit in SAP SRM. This allows an unauthenticated attacker to craft a malicious link. When clicked by a victim, the link redirects the browser to a malicious site, potentially causing low impact on confidentiality and integrity with no impact on the application's availability.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

Weakness Enumeration

Related Identifiers

BDU:2025-16186
CVE-2025-30010

Affected Products

Sap Srm