CVE-2025-27430
- EPSS 0.03%
- Veröffentlicht 11.03.2025 01:15:36
- Zuletzt bearbeitet 11.03.2025 01:15:36
Under certain conditions, an SSRF vulnerability in SAP CRM and SAP S/4HANA (Interaction Center) allows an attacker with low privileges to access restricted information. This flaw enables the attacker to send requests to internal network resources, th...
CVE-2023-27897
- EPSS 1.68%
- Veröffentlicht 11.04.2023 03:15:07
- Zuletzt bearbeitet 21.11.2024 07:53:39
In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application function to perform actions which they...
CVE-2021-33676
- EPSS 0.24%
- Veröffentlicht 14.07.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:09:20
A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privileges to compromise confidentiality, integrity, or availability of the system.
CVE-2018-2380
- EPSS 47.8%
- Veröffentlicht 01.03.2018 17:29:00
- Zuletzt bearbeitet 12.03.2025 20:37:50
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
CVE-2017-15296
- EPSS 0.11%
- Veröffentlicht 16.10.2017 16:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.
CVE-2017-15294
- EPSS 0.33%
- Veröffentlicht 16.10.2017 16:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.
CVE-2015-3980
- EPSS 0.23%
- Veröffentlicht 12.05.2015 20:59:02
- Zuletzt bearbeitet 12.04.2025 10:46:40
SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2097534.
CVE-2015-3979
- EPSS 0.65%
- Veröffentlicht 12.05.2015 20:59:01
- Zuletzt bearbeitet 12.04.2025 10:46:40
Unspecified vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary code via unknown vectors, aka SAP Security Note 2097534.
- EPSS 9.97%
- Veröffentlicht 06.11.2014 15:55:14
- Zuletzt bearbeitet 12.04.2025 10:46:40
The SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code via unspecified vectors.
- EPSS 0.54%
- Veröffentlicht 14.02.2014 15:55:07
- Zuletzt bearbeitet 11.04.2025 00:51:21
Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to an XML External Entity (XXE) issue.