CVE-2025-27430
- EPSS 0.03%
- Published 11.03.2025 01:15:36
- Last modified 11.03.2025 01:15:36
Under certain conditions, an SSRF vulnerability in SAP CRM and SAP S/4HANA (Interaction Center) allows an attacker with low privileges to access restricted information. This flaw enables the attacker to send requests to internal network resources, th...
CVE-2023-27897
- EPSS 1.68%
- Published 11.04.2023 03:15:07
- Last modified 21.11.2024 07:53:39
In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application function to perform actions which they...
CVE-2021-33676
- EPSS 0.24%
- Published 14.07.2021 12:15:08
- Last modified 21.11.2024 06:09:20
A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privileges to compromise confidentiality, integrity, or availability of the system.
CVE-2018-2380
- EPSS 47.8%
- Published 01.03.2018 17:29:00
- Last modified 12.03.2025 20:37:50
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
CVE-2017-15296
- EPSS 0.11%
- Published 16.10.2017 16:29:01
- Last modified 20.04.2025 01:37:25
The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.
CVE-2017-15294
- EPSS 0.33%
- Published 16.10.2017 16:29:00
- Last modified 20.04.2025 01:37:25
The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.
CVE-2015-3980
- EPSS 0.23%
- Published 12.05.2015 20:59:02
- Last modified 12.04.2025 10:46:40
SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2097534.
CVE-2015-3979
- EPSS 0.65%
- Published 12.05.2015 20:59:01
- Last modified 12.04.2025 10:46:40
Unspecified vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary code via unknown vectors, aka SAP Security Note 2097534.
- EPSS 9.97%
- Published 06.11.2014 15:55:14
- Last modified 12.04.2025 10:46:40
The SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code via unspecified vectors.
- EPSS 0.54%
- Published 14.02.2014 15:55:07
- Last modified 11.04.2025 00:51:21
Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to an XML External Entity (XXE) issue.