SAP
SAP Customer Relationship Management: vulnerabilities and CVEs
SAP Customer Relationship Management has 10 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 1 are listed by CISA as actively exploited.
CVEs10
Last 12 months0
Critical0
Actively exploited1
All vulnerabilities in the catalogue →⭐ Follow this technology
🔴 Actively exploited (CISA KEV)
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2018-2380 | Medium (6.6) | 29% | ⚠ Active exploitation | Mar 1, 2018 | SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to… |
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-27897 | Medium (6.3) | 0.65% | — | Apr 11, 2023 | In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application… |
| CVE-2021-33676 | High (7.2) | 0.91% | — | Jul 14, 2021 | A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privileges to compromise confidentiality, integrity, or availability of the system. |
| CVE-2018-2380 | Medium (6.6) | 29% | ⚠ Active exploitation | Mar 1, 2018 | SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to… |
| CVE-2017-15296 | High (8.8) | 0.55% | — | Oct 16, 2017 | The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964. |
| CVE-2017-15294 | Medium (6.1) | 0.98% | — | Oct 16, 2017 | The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964. |
| CVE-2015-3980 | High (7.5) | 1.4% | — | May 12, 2015 | SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2097534. |
| CVE-2015-3979 | High (7.5) | 2.4% | — | May 12, 2015 | Unspecified vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary code via unknown vectors, aka SAP Security Note 2097534. |
| CVE-2014-8669 | High (10) | 5.5% | — | Nov 6, 2014 | The SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code via unspecified vectors. |
| CVE-2014-1962 | Medium (5) | 1.5% | — | Feb 14, 2014 | Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to an XML External Entity (XXE) issue. |
| CVE-2013-7095 | High (10) | 2.1% | — | Dec 13, 2013 | The XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack vectors related to an XML External Entity (XXE) issue. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.
Other products by SAP
3D Visual Enterprise Viewer · 131Netweaver · 119Netweaver Application Server Abap · 110Businessobjects Business Intelligence Platform · 80Netweaver Application Server Java · 79S/4hana · 50Businessobjects Business Intelligence · 46Hana · 39Solution Manager · 37Business ONE · 35Abap Platform · 32Netweaver Enterprise Portal · 29