Supplier Relationship Management
11 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Supplier Relationship Management, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
Supplier Relationship Management CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 5 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 1 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 1 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 11 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High1
- Medium9
Latest CVEs
The 11 most recently published vulnerabilities affecting Supplier Relationship Management.
- CVE-2026-0513Open Redirect Vulnerability in SAP Supplier Relationship Management (SICF Handler in SRM Catalog)4.7
- CVE-2025-42920Cross-Site Scripting (XSS) vulnerability in SAP Supplier Relationship Management6.1
- CVE-2025-30018Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)8.6
- CVE-2025-30012Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)10.0
- CVE-2025-30011Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)5.3
- CVE-2025-30010Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)6.1
- CVE-2025-30009Multiple vulnerabilities in SAP Supplier Relationship Management (Live Auction Cockpit)6.1
- CVE-2023-39436Information Disclosure in SAP Supplier Relationship Management5.8
- CVE-2019-0361SAP Supplier Relationship Management (Master Data Management Catalog - SRM_MDM_CAT, before versions 3.73, 7.31, 7.32) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Sc...6.1
- CVE-2014-4159Open redirect vulnerability in in la/umTestSSO.jsp in SAP Supplier Relationship Management (SRM) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via ...5.8
- CVE-2014-4161Cross-site scripting (XSS) vulnerability in la/umTestSSO.jsp in SAP Supplier Relationship Management (SRM) allows remote attackers to inject arbitrary web script or HTML via the url parameter.4.3
Product grouping is registry-driven, with AI assist and human review. How it works