Medium severity6.1NVD Advisory· Published Oct 16, 2017· Updated May 13, 2026
CVE-2017-15294
CVE-2017-15294
Description
The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.
Affected products
8cpe:2.3:a:sap:customer_relationship_management:700:*:*:*:*:*:*:*+ 7 more
- cpe:2.3:a:sap:customer_relationship_management:700:*:*:*:*:*:*:*
- cpe:2.3:a:sap:customer_relationship_management:701:*:*:*:*:*:*:*
- cpe:2.3:a:sap:customer_relationship_management:702:*:*:*:*:*:*:*
- cpe:2.3:a:sap:customer_relationship_management:730:*:*:*:*:*:*:*
- cpe:2.3:a:sap:customer_relationship_management:731:*:*:*:*:*:*:*
- cpe:2.3:a:sap:customer_relationship_management:732:*:*:*:*:*:*:*
- cpe:2.3:a:sap:customer_relationship_management:733:*:*:*:*:*:*:*
- cpe:2.3:a:sap:customer_relationship_management:754:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/99532nvdThird Party AdvisoryVDB Entry
- blogs.sap.com/2017/07/11/sap-security-patch-day-july-2017/nvdIssue TrackingVendor Advisory
- erpscan.io/advisories/erpscan-17-035-xss-crm-administration-console-java/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.