CNNVD-202509-1453 Information

CNNVD ID

CNNVD-202509-1453

CVE-2025-42920

  • CNNVD Published: 2025-09-09

Description (Chinese)

SAP Supplier Relationship Management(SRM)是德国思爱普(SAP)公司的一套供应商关系管理解决方案。该产品实现了企业内以及供应商之间采购和购置流程的自动化,并提供发票开具等功能。 SAP Supplier Relationship Management存在跨站脚本漏洞,该漏洞源于跨站脚本漏洞,可能导致执行恶意内容。

Description (English)

SAP Suplier Relationship Management (SRM) is a supplier relationship management solution for SAP, Germany. The product automates the procurement and acquisition process within the enterprise and between suppliers and provides functions such as invoicing. SAP Suppleier Relationship Management has a cross-site script loophole, which stems from a cross-site script loophole and may lead to the implementation of malicious content.

Hazard Level

High

Vulnerability Type

跨站脚本

Affected Vendor

思爱普

Published

2025-09-09

Last Modified

2026-02-24

References

https://me.sap.com/notes/3647098 https://url.sap/sapsecuritypatchday

Patch

https://me.sap.com/notes/3647098

Share on: