VYPR

CRM

by SAP

CVEs (13)

  • CVE-2026-0488CriFeb 10, 2026
    risk 0.64cvss 9.9epss 0.00

    An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database…

  • CVE-2017-15296HigOct 16, 2017
    risk 0.57cvss 8.8epss 0.01

    The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.

  • CVE-2021-33676HigJul 14, 2021
    risk 0.47cvss 7.2epss 0.01

    A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privileges to compromise confidentiality, integrity, or availability of the system.

  • CVE-2023-30742MedMay 9, 2023
    risk 0.40cvss 6.1epss 0.00

    SAP CRM (WebClient UI) - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, WEBCUIF 700, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in a stored…

  • CVE-2017-15294MedOct 16, 2017
    risk 0.40cvss 6.1epss 0.01

    The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.

  • CVE-2023-27897MedApr 11, 2023
    risk 0.39cvss 6.0epss 0.01

    In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application function to perform actions which they would not normally be…

  • CVE-2023-29189MedApr 11, 2023
    risk 0.35cvss 5.4epss 0.00

    SAP CRM (WebClient UI) - versions S4FND 102, 103, 104, 105, 106, 107, WEBCUIF, 700, 701, 731, 730, 746, 747, 748, 800, 801, allows an authenticated attacker to modify HTTP verbs used in requests to the web server. This application is exposed over the network and successful…

  • CVE-2024-39598MedJul 9, 2024
    risk 0.33cvss 5.0epss 0.00

    SAP CRM (WebClient UI Framework) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in information disclosure. It has no impact on integrity and…

  • CVE-2025-27430LowMar 11, 2025
    risk 0.23cvss 3.5epss 0.00

    Under certain conditions, an SSRF vulnerability in SAP CRM and SAP S/4HANA (Interaction Center) allows an attacker with low privileges to access restricted information. This flaw enables the attacker to send requests to internal network resources, thereby compromising the…

  • CVE-2015-3980May 12, 2015
    risk 0.00cvss epss 0.01

    SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2097534.

  • CVE-2015-3979May 12, 2015
    risk 0.00cvss epss 0.02

    Unspecified vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary code via unknown vectors, aka SAP Security Note 2097534.

  • CVE-2014-1962Feb 14, 2014
    risk 0.00cvss epss 0.01

    Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to an XML External Entity (XXE) issue.

  • CVE-2013-7095Dec 13, 2013
    risk 0.00cvss epss 0.02

    The XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack vectors related to an XML External Entity (XXE) issue.