Advisory
A note with CVSS 8.6 for component SRM-LA was released by SAP on 13.05.2025. The correction/advisory 3578900 was described with "[CVE-2025-30018] Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)" and affects the system type Java.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is cross-site scripting (xss)information disclosureopen redirect within Java.
Risk specification
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) relies on a deprecated Java applet, which exposes the application to multiple vulnerabilities. An unauthenticated attacker could exploit these weaknesses, potentially compromising system security.Solution
The deprecated software component version has been removed to eliminate associated vulnerabilities and enhance overall system security.
Affected System
SAP Netweaver Application Server Java is part of the SAP NetWeaver Application Platform. It provides the complete infrastructure for deploying and running Java applications.
- The AS Java Home: SAP Netweaver Application Server Java wiki
- A dedicated SAP NetWeaver 7.40 Application Server for Java Security Guide exists.
The advisory is valid for