Customer Relationship Management
by SAP
CVEs (11)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-2380 | Med | 0.66 | 6.6 | 0.29 | KEV | Mar 1, 2018 | SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs. | |
| CVE-2017-15296 | Hig | 0.57 | 8.8 | 0.01 | Oct 16, 2017 | The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964. | ||
| CVE-2021-33676 | Hig | 0.47 | 7.2 | 0.01 | Jul 14, 2021 | A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privileges to compromise confidentiality, integrity, or availability of the system. | ||
| CVE-2017-15294 | Med | 0.40 | 6.1 | 0.01 | Oct 16, 2017 | The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964. | ||
| CVE-2023-27897 | Med | 0.39 | 6.0 | 0.01 | Apr 11, 2023 | In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application function to perform actions which they would not normally be… | ||
| CVE-2019-0368 | Med | 0.35 | 5.4 | 0.01 | Oct 8, 2019 | SAP Customer Relationship Management (Email Management), versions: S4CRM before 1.0 and 2.0, BBPCRM before 7.0, 7.01, 7.02, 7.12, 7.13 and 7.14, does not sufficiently encode user-controlled inputs within the mail client resulting in Cross-Site Scripting vulnerability. | ||
| CVE-2015-3980 | 0.00 | — | 0.01 | May 12, 2015 | SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2097534. | |||
| CVE-2015-3979 | 0.00 | — | 0.02 | May 12, 2015 | Unspecified vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary code via unknown vectors, aka SAP Security Note 2097534. | |||
| CVE-2014-8669 | 0.00 | — | 0.05 | Nov 6, 2014 | The SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code via unspecified vectors. | |||
| CVE-2014-1962 | 0.00 | — | 0.01 | Feb 14, 2014 | Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to an XML External Entity (XXE) issue. | |||
| CVE-2013-7095 | 0.00 | — | 0.02 | Dec 13, 2013 | The XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack vectors related to an XML External Entity (XXE) issue. |
- risk 0.66cvss 6.6epss 0.29
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
- risk 0.57cvss 8.8epss 0.01
The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.
- risk 0.47cvss 7.2epss 0.01
A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privileges to compromise confidentiality, integrity, or availability of the system.
- risk 0.40cvss 6.1epss 0.01
The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.
- risk 0.39cvss 6.0epss 0.01
In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application function to perform actions which they would not normally be…
- risk 0.35cvss 5.4epss 0.01
SAP Customer Relationship Management (Email Management), versions: S4CRM before 1.0 and 2.0, BBPCRM before 7.0, 7.01, 7.02, 7.12, 7.13 and 7.14, does not sufficiently encode user-controlled inputs within the mail client resulting in Cross-Site Scripting vulnerability.
- CVE-2015-3980May 12, 2015risk 0.00cvss —epss 0.01
SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2097534.
- CVE-2015-3979May 12, 2015risk 0.00cvss —epss 0.02
Unspecified vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary code via unknown vectors, aka SAP Security Note 2097534.
- CVE-2014-8669Nov 6, 2014risk 0.00cvss —epss 0.05
The SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code via unspecified vectors.
- CVE-2014-1962Feb 14, 2014risk 0.00cvss —epss 0.01
Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to an XML External Entity (XXE) issue.
- CVE-2013-7095Dec 13, 2013risk 0.00cvss —epss 0.02
The XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack vectors related to an XML External Entity (XXE) issue.