Vulnerabilities
Vulnerable Software
In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform. Depending on the function executed, the attack can can have limited impact on confidentiality and integrity of non-critical user or application data and application availability.
CVSS Score
6.0
EPSS Score
0.017
Published
2023-04-11
A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privileges to compromise confidentiality, integrity, or availability of the system.
CVSS Score
6.8
EPSS Score
0.002
Published
2021-07-14
CVE-2018-2380
Known exploited
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
CVSS Score
6.6
EPSS Score
0.453
Published
2018-03-01
The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.
CVSS Score
8.8
EPSS Score
0.001
Published
2017-10-16
The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.
CVSS Score
6.1
EPSS Score
0.003
Published
2017-10-16
SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2097534.
CVSS Score
7.5
EPSS Score
0.002
Published
2015-05-12
Unspecified vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary code via unknown vectors, aka SAP Security Note 2097534.
CVSS Score
7.5
EPSS Score
0.007
Published
2015-05-12
The SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code via unspecified vectors.
CVSS Score
10.0
EPSS Score
0.1
Published
2014-11-06
Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to an XML External Entity (XXE) issue.
CVSS Score
5.0
EPSS Score
0.005
Published
2014-02-14
The XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack vectors related to an XML External Entity (XXE) issue.
CVSS Score
10.0
EPSS Score
0.013
Published
2013-12-13


Contact Us

Shodan ® - All rights reserved