Show filters
146 Total Results
Displaying 131-140 of 146
Sort by:
Attacker Value
Unknown

CVE-2015-3980

Disclosure Date: May 12, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2097534.
0
Attacker Value
Unknown

CVE-2014-8661

Disclosure Date: November 06, 2014 (last updated October 05, 2023)
The SAP CRM Internet Sales module allows remote attackers to execute arbitrary commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-8669

Disclosure Date: November 06, 2014 (last updated October 05, 2023)
The SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-4159

Disclosure Date: June 13, 2014 (last updated October 05, 2023)
Open redirect vulnerability in in la/umTestSSO.jsp in SAP Supplier Relationship Management (SRM) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
0
Attacker Value
Unknown

CVE-2014-4161

Disclosure Date: June 13, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in la/umTestSSO.jsp in SAP Supplier Relationship Management (SRM) allows remote attackers to inject arbitrary web script or HTML via the url parameter.
0
Attacker Value
Unknown

CVE-2014-1962

Disclosure Date: February 14, 2014 (last updated October 05, 2023)
Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to an XML External Entity (XXE) issue.
0
Attacker Value
Unknown

CVE-2013-7095

Disclosure Date: December 13, 2013 (last updated October 05, 2023)
The XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack vectors related to an XML External Entity (XXE) issue.
0
Attacker Value
Unknown

CVE-2013-0225

Disclosure Date: March 19, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the User Relationships module 6.x-1.x before 6.x-1.4 and 7.x-1.x before 7.x-1.0-alpha5 for Drupal allows remote authenticated users with the "administer user relationships" permission to inject arbitrary web script or HTML via a relationship name.
0
Attacker Value
Unknown

CVE-2012-3818

Disclosure Date: June 29, 2012 (last updated October 04, 2023)
The fpm exporter in Revelation 0.4.13-2 and earlier encrypts the version number but not the password when exporting a file, which might allow local users to obtain sensitive information.
0
Attacker Value
Unknown

CVE-2012-2743

Disclosure Date: June 27, 2012 (last updated October 04, 2023)
Revelation 0.4.13-2 and earlier does not iterate through SHA hashing algorithms for AES encryption, which makes it easier for context-dependent attackers to guess passwords via a brute force attack.
0