Vulnerabilities (CVE)

Filtered by vendor Sap Subscribe
Filtered by product Customer Relationship Management
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-15294 1 Sap 1 Customer Relationship Management 2019-04-17 4.3 MEDIUM 6.1 MEDIUM
The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.
CVE-2018-2380 1 Sap 1 Customer Relationship Management 2018-03-23 6.5 MEDIUM 6.6 MEDIUM
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.