PT-2025-15371 · Sap · Sap Erp Bw Business Content

CVE-2025-30013

·

Publicado

2025-04-08

·

Atualizado

2025-04-08

CVSS v2.0

6.8

Média

VetorAV:L/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: SAP ERP BW Business Content (affected versions not specified)
Description: The issue is related to OS Command Injection through certain function modules. When these modules are executed with elevated privileges, they improperly handle user input, allowing an attacker to inject arbitrary OS commands. This poses a significant security risk to the confidentiality, integrity, and availability of the application.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2025-04844
CVE-2025-30013

Produtos afetados

Sap Erp Bw Business Content