← Back

Customer Relationship Management

customer_relationship_management

Vendor: Sap • 10 CVEs

CVEs (10)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Sap
1Customer Relationship Management
Jun 17, 2026
Apr 11, 2023
N/A· v4
6.3 MEDIUM· v3
N/A· v2
In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application function...Show more
In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform. Depending on the function executed, the attack can can have limited impact on confidentiality and integrity of non-critical user or application data and application availability. Show less
1Sap
1Customer Relationship Management
Jun 17, 2026
Jul 14, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privileges to compromise confidentiality, integrity, or availability of the system.
1Sap
1Customer Relationship Management
Oct 31, 2025
Mar 1, 2018
N/A· v4
6.6 MEDIUM· v3
6.5 MEDIUM· v2
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to t...Show more
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.Show less
1Sap
1Customer Relationship Management
May 13, 2026
Oct 16, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.
1Sap
1Customer Relationship Management
May 13, 2026
Oct 16, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.
1Sap
1Customer Relationship Management
May 6, 2026
May 12, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2097534.
1Sap
1Customer Relationship Management
May 6, 2026
May 12, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary code via unknown vectors, aka SAP Security Note 2097534.
1Sap
1Customer Relationship Management
May 6, 2026
Nov 6, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
The SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code via unspecified vectors.
1Sap
1Customer Relationship Management
Apr 29, 2026
Feb 14, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to an XML External Entity (XXE) issue.
1Sap
1Customer Relationship Management
Apr 29, 2026
Dec 13, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
The XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack vectors related to an XML External Entity (XXE) issue.