VYPR
Medium severity5.4NVD Advisory· Published Oct 8, 2019· Updated Jun 17, 2026

CVE-2019-0368

CVE-2019-0368

Description

SAP Customer Relationship Management (Email Management), versions: S4CRM before 1.0 and 2.0, BBPCRM before 7.0, 7.01, 7.02, 7.12, 7.13 and 7.14, does not sufficiently encode user-controlled inputs within the mail client resulting in Cross-Site Scripting vulnerability.

Affected products

13
  • cpe:2.3:a:sap:customer_relationship_management_bbpcrm:7.01:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:sap:customer_relationship_management_bbpcrm:7.01:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:customer_relationship_management_bbpcrm:7.02:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:customer_relationship_management_bbpcrm:7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:customer_relationship_management_bbpcrm:7.12:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:customer_relationship_management_bbpcrm:7.13:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:customer_relationship_management_bbpcrm:7.14:*:*:*:*:*:*:*
  • cpe:2.3:a:sap:customer_relationship_management_s4crm:1.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sap:customer_relationship_management_s4crm:1.0:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:customer_relationship_management_s4crm:2.0:*:*:*:*:*:*:*
  • SAP/S4CRMllm-create
    Range: before 1.0 and 2.0
  • SAP/BBPCRMllm-create
    Range: before 7.0, 7.01, 7.02, 7.12, 7.13 and 7.14
  • Range: before 1.0 and 2.0 (S4CRM), before 7.0, 7.01, 7.02, 7.12, 7.13 and 7.14 (BBPCRM)
  • SAP SE/SAP Customer Relationship Management (Email Management - BBPCRM)v5
    Range: < 7.0
  • SAP SE/SAP Customer Relationship Management (Email Management - S4CRM)v5
    Range: < 1.0

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.