CVE-2025-30013
Last modified
CVE-2025-30013 is a medium-severity vulnerability rated 6.7/10 on the CVSS scale. SAP ERP BW Business Content is vulnerable to OS Command Injection through certain function modules. These function modules, when executed with elevated privileges, improperly handle user input, allowing attacker to inject arbitrary OS commands. EPSS estimates a 0.75% chance of exploitation in the next 30 days.
Description
SAP ERP BW Business Content is vulnerable to OS Command Injection through certain function modules. These function modules, when executed with elevated privileges, improperly handle user input, allowing attacker to inject arbitrary OS commands. This vulnerability allows the execution of unintended commands on the underlying system, posing a significant security risk to the confidentiality, integrity and availability of the application.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-30013?
How severe is CVE-2025-30013?
How do I fix CVE-2025-30013?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-30008HestiaCP before 1.9.5 contains a stored cross-site scripting…5.4
- CVE-2025-30009he Live Auction Cockpit in SAP Supplier Relationship Managem…6.1
- CVE-2025-3001A vulnerability classified as critical was found in PyTorch …5.3
- CVE-2025-30010The Live Auction Cockpit in SAP Supplier Relationship Manage…6.1
- CVE-2025-30011The Live Auction Cockpit in SAP Supplier Relationship Manage…5.3
- CVE-2025-30012The Live Auction Cockpit in SAP Supplier Relationship Manage…9.8
- CVE-2025-30014SAP Capital Yield Tax Management has directory traversal vul…7.7
- CVE-2025-30015Due to incorrect memory address handling in ABAP SQL of SAP …4.1
- CVE-2025-30016SAP Financial Consolidation allows an unauthenticated attack…9.8
- CVE-2025-30017Due to a missing authorization check, an authenticated attac…4.4
- CVE-2025-30018The Live Auction Cockpit in SAP Supplier Relationship Manage…7.5
- CVE-2025-3002A vulnerability, which was classified as critical, has been …7.3
Are you affected by CVE-2025-30013?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
