Advisory
A note with CVSS 10.0 for component SRM-LA was released by SAP on 13.05.2025. The correction/advisory 3578900 was described with "[CVE-2025-30012] Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)" and affects the system type Java.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is cross-site scripting (xss)information disclosureopen redirect within Java.
Risk specification
This advisory has been updated to include revised information regarding CVSS scores and associated symptoms. The Live Auction Cockpit component in SAP Supplier Relationship Management (SRM) relies on a deprecated Java applet, which exposes the system to multiple vulnerabilities. These flaws could be exploited by an unauthenticated attacker, posing significant security risks.Solution
The deprecated software component has been removed.
Affected System
SAP Netweaver Application Server Java is part of the SAP NetWeaver Application Platform. It provides the complete infrastructure for deploying and running Java applications.
- The AS Java Home: SAP Netweaver Application Server Java wiki
- A dedicated SAP NetWeaver 7.40 Application Server for Java Security Guide exists.
The advisory is valid for