cbcvebase.
CVE-2023-29189
published 2023-04-11

CVE-2023-29189: SAP CRM (WebClient UI) - versions S4FND 102, 103, 104, 105, 106, 107, WEBCUIF, 700, 701, 731, 730, 746, 747, 748, 800, 801, allows an authenticated attacker to…

PriorityP429medium5.4CVSS 3.1
AVNACLPRLUINSUCLILAN
EPSS
0.44%
35.8th percentile
SAP CRM (WebClient UI) - versions S4FND 102, 103, 104, 105, 106, 107, WEBCUIF, 700, 701, 731, 730, 746, 747, 748, 800, 801, allows an authenticated attacker to modify HTTP verbs used in requests to the web server. This application is exposed over the network and successful exploitation can lead to exposure of form fields

Affected

28 ranges· showing 25
VendorProductVersion rangeFixed in
sapcrm
sapcrm
sapcrm
sapcrm
sapcrm
sapcrm
sapcrm
sapcrm
sapcrm
sapcrm
sapcrm
sapcrm
sapcrm
sapcrm
sapcrm
sapcustomer_relationship_management_s4fnd
sapcustomer_relationship_management_s4fnd
sapcustomer_relationship_management_s4fnd
sapcustomer_relationship_management_s4fnd
sapcustomer_relationship_management_webclient_ui
sapcustomer_relationship_management_webclient_ui
sapcustomer_relationship_management_webclient_ui
sapcustomer_relationship_management_webclient_ui
sapcustomer_relationship_management_webclient_ui
sapcustomer_relationship_management_webclient_ui
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.