Home/Product/sap supplier relationship management
Product

sap supplier relationship management

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-0513
all versions
Due to an Open Redirect Vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog), an unauthenticated at
4.7MEDIUM
CVE-2025-42920
all versions
Due to a Cross-Site Scripting (XSS) vulnerability in the SAP Supplier Relationship Management, an unauthenticated attacker could g
6.1MEDIUM
CVE-2025-30018
all versions
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) allows an unauthenticated attacker to submit an application
8.6HIGH
CVE-2025-30012
all versions
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component, which allows an un
10.0CRITICAL
CVE-2025-30011
all versions
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected
5.3MEDIUM
CVE-2025-30010
all versions
The Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected
6.1MEDIUM
CVE-2025-30009
all versions
he Live Auction Cockpit in SAP Supplier Relationship Management (SRM) uses a deprecated java applet component within the affected
6.1MEDIUM
CVE-2023-39436
all versions
SAP Supplier Relationship Management -versions 600, 602, 603, 604, 605, 606, 616, 617, allows an unauthorized attacker to discover
5.8MEDIUM
CVE-2019-0361
all versions
SAP Supplier Relationship Management (Master Data Management Catalog - SRM_MDM_CAT, before versions 3.73, 7.31, 7.32) does not suf
6.1MEDIUM
CVE-2014-4161
all versions
Cross-site scripting (XSS) vulnerability in la/umTestSSO.jsp in SAP Supplier Relationship Management (SRM) allows remote attackers
CVE-2014-4159
all versions
Open redirect vulnerability in la/umTestSSO.jsp in SAP Supplier Relationship Management (SRM) allows remote attackers to redir
threatengine.sh