SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityDeferred

CVE-2025-30013

SAP ERP BW Business Content is vulnerable to OS Command Injection through certain function modules.

MEDIUM 6.7EPSS 0.79%

Does this matter?

Lower severity and a low EPSS score (0.79%). Track it; it rarely justifies an emergency change on its own.

Description

SAP ERP BW Business Content is vulnerable to OS Command Injection through certain function modules. These function modules, when executed with elevated privileges, improperly handle user input, allowing attacker to inject arbitrary OS commands. This vulnerability allows the execution of unintended commands on the underlying system, posing a significant security risk to the confidentiality, integrity and availability of the application.

CVSS 3.1
6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.79% probability · 54th percentile
CISA KEV
Not listed
Weakness
CWE-94
Source
cna@sap.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.