VendorsSAPcustomer_relationship_management7.02
Vulnerabilities

SAP Customer Relationship Management 7.02

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2013-7095
The XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack vectors related to an XML External Entity (XXE) issue.
Published 2013-12-13 · Modified
10.0EPSS 0.021
CVE-2018-2380
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
Published 2018-03-01 · Analyzed
6.6KEV1 PoCEPSS 0.289
CVE-2014-1962
Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to an XML External Entity (XXE) issue.
Published 2014-02-14 · Modified
5.0EPSS 0.015