VYPR

SAP Contract Lifecycle Management

by SAP

CVEs (4)

  • CVE-2022-41273Dec 13, 2022
    risk 0.00cvss epss 0.00

    Due to improper input sanitization in SAP Sourcing and SAP Contract Lifecycle Management - version 1100, an attacker can redirect a user to a malicious website. In order to perform this attack, the attacker sends an email to the victim with a manipulated link that appears to be…

  • CVE-2019-20155Jan 5, 2020
    risk 0.00cvss epss 0.02

    An issue was discovered in report_edit.jsp in Determine (formerly Selectica) Contract Lifecycle Management (CLM) v5.4. Any authenticated user may execute Groovy code when generating a report, resulting in arbitrary code execution on the underlying server.

  • CVE-2019-20154Jan 5, 2020
    risk 0.00cvss epss 0.01

    An issue was discovered in Determine (formerly Selectica) Contract Lifecycle Management (CLM) v5.4. A cross-site scripting (XSS) vulnerability in multiple getchart.jsp parameters allows remote attackers to inject arbitrary web script or HTML.

  • CVE-2019-20153Jan 5, 2020
    risk 0.00cvss epss 0.01

    An issue was discovered in Determine (formerly Selectica) Contract Lifecycle Management (CLM) in v5.4. An XML external entity (XXE) vulnerability in the upload definition feature in definition_upload_attach.jsp allows authenticated remote attackers to read arbitrary files…