« Back to list

SAP

SAP Customer Relationship Management: vulnerabilities and CVEs

SAP Customer Relationship Management has 10 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 1 are listed by CISA as actively exploited.

CVEs10
Last 12 months0
Critical0
Actively exploited1

All vulnerabilities in the catalogue →⭐ Follow this technology

🔴 Actively exploited (CISA KEV)

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2018-2380Medium (6.6)29%⚠ Active exploitationMar 1, 2018
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to…

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2023-27897Medium (6.3)0.65%—Apr 11, 2023
In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application…
CVE-2021-33676High (7.2)0.91%—Jul 14, 2021
A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privileges to compromise confidentiality, integrity, or availability of the system.
CVE-2018-2380Medium (6.6)29%⚠ Active exploitationMar 1, 2018
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to…
CVE-2017-15296High (8.8)0.55%—Oct 16, 2017
The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.
CVE-2017-15294Medium (6.1)0.98%—Oct 16, 2017
The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.
CVE-2015-3980High (7.5)1.4%—May 12, 2015
SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2097534.
CVE-2015-3979High (7.5)2.4%—May 12, 2015
Unspecified vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary code via unknown vectors, aka SAP Security Note 2097534.
CVE-2014-8669High (10)5.5%—Nov 6, 2014
The SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code via unspecified vectors.
CVE-2014-1962Medium (5)1.5%—Feb 14, 2014
Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to an XML External Entity (XXE) issue.
CVE-2013-7095High (10)2.1%—Dec 13, 2013
The XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack vectors related to an XML External Entity (XXE) issue.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1005 Data from Local System1
  2. T1210 Exploitation of Remote Services1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by SAP