CVE-2025-30017
Last modified
CVE-2025-30017 is a medium-severity vulnerability rated 4.4/10 on the CVSS scale. Due to a missing authorization check, an authenticated attacker could upload a file as a template for solution documentation in SAP Solution Manager 7.1. After successful exploitation, an attacker can cause limited impact on the integrity and availability of the application.. EPSS estimates a 0.12% chance of exploitation in the next 30 days.
Description
Due to a missing authorization check, an authenticated attacker could upload a file as a template for solution documentation in SAP Solution Manager 7.1. After successful exploitation, an attacker can cause limited impact on the integrity and availability of the application.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-30017?
How severe is CVE-2025-30017?
How do I fix CVE-2025-30017?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-30011The Live Auction Cockpit in SAP Supplier Relationship Manage…5.3
- CVE-2025-30012The Live Auction Cockpit in SAP Supplier Relationship Manage…9.8
- CVE-2025-30013SAP ERP BW Business Content is vulnerable to OS Command Inje…6.7
- CVE-2025-30014SAP Capital Yield Tax Management has directory traversal vul…7.7
- CVE-2025-30015Due to incorrect memory address handling in ABAP SQL of SAP …4.1
- CVE-2025-30016SAP Financial Consolidation allows an unauthenticated attack…9.8
- CVE-2025-30018The Live Auction Cockpit in SAP Supplier Relationship Manage…7.5
- CVE-2025-3002A vulnerability, which was classified as critical, has been …7.3
- CVE-2025-30022CM Soluces Informatica Ltda Auto Atendimento 1.x.x was disco…6.8
- CVE-2025-30023The communication protocol used between client and server ha…9
- CVE-2025-30024The communication protocol used between client and server ha…6.8
- CVE-2025-30025The communication protocol used between the server process a…7.8
Are you affected by CVE-2025-30017?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
