cbcvebase.

Sap Crm vulnerabilities

3 known vulnerabilities affecting sap/crm.

Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM3

Vulnerabilities

Page 1 of 1
CVE-2023-27897P3MEDIUMCVSS 6.3v700v701+3 more2023-04-11
CVE-2023-27897 [MEDIUM] CWE-94 CVE-2023-27897: In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administr In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform. Depending on the function executed, the attack can can ha
nvd
CVE-2023-29189P4MEDIUMCVSS 5.4vS4FND 102vS4FND 103+13 more2023-04-11
CVE-2023-29189 [MEDIUM] CWE-23 CVE-2023-29189: SAP CRM (WebClient UI) - versions S4FND 102, 103, 104, 105, 106, 107, WEBCUIF, 700, 701, 731, 730, 7 SAP CRM (WebClient UI) - versions S4FND 102, 103, 104, 105, 106, 107, WEBCUIF, 700, 701, 731, 730, 746, 747, 748, 800, 801, allows an authenticated attacker to modify HTTP verbs used in requests to the web server. This application is exposed over the network and successful exploitation can lead to exposure of form fields
nvd
CVE-2023-24525P4MEDIUMCVSS 5.4vWEBCUIF 748v800+3 more2023-02-14
CVE-2023-24525 [MEDIUM] CWE-79 CVE-2023-24525: SAP CRM WebClient UI - versions WEBCUIF 748, 800, 801, S4FND 102, 103, does not sufficiently encode SAP CRM WebClient UI - versions WEBCUIF 748, 800, 801, S4FND 102, 103, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. On successful exploitation an authenticated attacker can cause limited impact on confidentiality of the application.
nvd
Sap Crm vulnerabilities | cvebase