Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-10100 | SAP ERP BW Business Content is vulnerable to OS Command Injection through certain function modules. These function modules, when executed with elevated privileges, improperly handle user input, allowing attacker to inject arbitrary OS commands. This vulnerability allows the execution of unintended commands on the underlying system, posing a significant security risk to the confidentiality, integrity and availability of the application. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 08 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Apr 2025 07:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP ERP BW Business Content is vulnerable to OS Command Injection through certain function modules. These function modules, when executed with elevated privileges, improperly handle user input, allowing attacker to inject arbitrary OS commands. This vulnerability allows the execution of unintended commands on the underlying system, posing a significant security risk to the confidentiality, integrity and availability of the application. | |
| Title | Code Injection vulnerability in SAP ERP BW Business Content | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-04-10T03:55:32.003Z
Reserved: 2025-03-13T18:03:35.488Z
Link: CVE-2025-30013
Updated: 2025-04-08T13:27:21.392Z
Status : Awaiting Analysis
Published: 2025-04-08T08:15:17.023
Modified: 2025-04-08T18:13:53.347
Link: CVE-2025-30013
No data.
OpenCVE Enrichment
No data.
EUVD