Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2023-27897

Disclosure Date: April 11, 2023 (last updated October 08, 2023)
In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform. Depending on the function executed, the attack can can have limited impact on confidentiality and integrity of non-critical user or application data and application availability.
Attacker Value
Unknown

CVE-2021-33676

Disclosure Date: July 14, 2021 (last updated November 28, 2024)
A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privileges to compromise confidentiality, integrity, or availability of the system.
Attacker Value
Unknown

CVE-2017-15296

Disclosure Date: October 16, 2017 (last updated November 26, 2024)
The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.
0
Attacker Value
Unknown

CVE-2017-15294

Disclosure Date: October 16, 2017 (last updated November 26, 2024)
The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.
0