CVE-2025-30013
Code Injection vulnerability in SAP ERP BW Business Content
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
SAP ERP BW Business Content is vulnerable to OS Command Injection through certain function modules. These function modules, when executed with elevated privileges, improperly handle user input, allowing attacker to inject arbitrary OS commands. This vulnerability allows the execution of unintended commands on the underlying system, posing a significant security risk to the confidentiality, integrity and availability of the application.
SAP ERP BW Business Content es vulnerable a la inyección de comandos del sistema operativo a través de ciertos módulos de función. Estos módulos, al ejecutarse con privilegios elevados, gestionan incorrectamente la entrada del usuario, lo que permite a un atacante inyectar comandos arbitrarios del sistema operativo. Esta vulnerabilidad permite la ejecución de comandos no deseados en el sistema subyacente, lo que supone un riesgo de seguridad significativo para la confidencialidad, integridad y disponibilidad de la aplicación.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2025-03-13 CVE Reserved
- 2025-04-08 CVE Published
- 2025-04-10 CVE Updated
- 2025-04-14 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-94: Improper Control of Generation of Code ('Code Injection')
CAPEC
References (2)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
SAP SE Search vendor "SAP SE" | SAP ERP BW Business Content Search vendor "SAP SE" for product "SAP ERP BW Business Content" | 737 Search vendor "SAP SE" for product "SAP ERP BW Business Content" and version "737" | en |
Affected
| ||||||
SAP SE Search vendor "SAP SE" | SAP ERP BW Business Content Search vendor "SAP SE" for product "SAP ERP BW Business Content" | 747 Search vendor "SAP SE" for product "SAP ERP BW Business Content" and version "747" | en |
Affected
| ||||||
SAP SE Search vendor "SAP SE" | SAP ERP BW Business Content Search vendor "SAP SE" for product "SAP ERP BW Business Content" | 757 Search vendor "SAP SE" for product "SAP ERP BW Business Content" and version "757" | en |
Affected
|