VYPR

Customer Relationship Management

Sign in to watch

by SAP

CVEs (7)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2017-15296Hig0.578.80.00Oct 16, 2017The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.
CVE-2017-15294Med0.406.10.00Oct 16, 2017The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.
CVE-2014-86690.010.10Nov 6, 2014The SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code via unspecified vectors.
CVE-2015-39800.000.00May 12, 2015SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2097534.
CVE-2015-39790.000.01May 12, 2015Unspecified vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary code via unknown vectors, aka SAP Security Note 2097534.
CVE-2014-19620.000.01Feb 14, 2014Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to an XML External Entity (XXE) issue.
CVE-2013-70950.000.01Dec 13, 2013The XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack vectors related to an XML External Entity (XXE) issue.