Vulnerability Description
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request with a crafted XML file which when parsed, enables the attacker to access sensitive files and data. This vulnerability has a high impact on the application's confidentiality, with no effect on integrity and availability of the application.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Supplier Relationship Management | 7.14 |
Related Weaknesses (CWE)
References
- https://me.sap.com/notes/3578900Permissions Required
- https://url.sap/sapsecuritypatchdayNot Applicable
FAQ
What is CVE-2025-30018?
CVE-2025-30018 is a vulnerability with a CVSS score of 8.6 (HIGH). The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application servlet request with a crafted XML file which when parsed, enables th...
How severe is CVE-2025-30018?
CVE-2025-30018 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-30018?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Supplier Relationship Management.