VendorsSAPcustomer_relationship_managementall versions
Vulnerabilities

SAP Customer Relationship Management

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2014-8669
The SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code via unspecified vectors.
Published 2014-11-06 · Modified
10.0EPSS 0.055
CVE-2013-7095
The XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack vectors related to an XML External Entity (XXE) issue.
Published 2013-12-13 · Modified
10.0EPSS 0.021
CVE-2017-15296
The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.
Published 2017-10-16 · Modified
8.8EPSS 0.005
CVE-2015-3979
Unspecified vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary code via unknown vectors, aka SAP Security Note 2097534.
Published 2015-05-12 · Modified
7.5EPSS 0.024
CVE-2015-3980
SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2097534.
Published 2015-05-12 · Modified
7.5EPSS 0.014
CVE-2021-33676
A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privileges to compromise confidentiality, integrity, or availability of the system.
Published 2021-07-14 · Modified
7.2EPSS 0.009
CVE-2018-2380
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
Published 2018-03-01 · Analyzed
6.6KEV1 PoCEPSS 0.289
CVE-2023-27897
Code Injection vulnerability in SAP CRM
Published 2023-04-11 · Modified
6.3EPSS 0.007
CVE-2017-15294
The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.
Published 2017-10-16 · Modified
6.1EPSS 0.010
CVE-2014-1962
Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to an XML External Entity (XXE) issue.
Published 2014-02-14 · Modified
5.0EPSS 0.015