Home/Product/sap customer relationship management
Product

sap customer relationship management

19 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-7078
<= 1.3.9
A vulnerability classified as problematic was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.3.9. This vulnerability affects un
4.3MEDIUM
CVE-2024-57161
all versions
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaWorkReport/edit.html
4.3MEDIUM
CVE-2024-57160
all versions
07FLYCMS V1.3.9 was discovered to contain a Cross-Site Request Forgery (CSRF) via /erp.07fly.net:80/oa/OaTask/edit.html.
4.3MEDIUM
CVE-2024-9904
>= 1.0.0 and <= 1.2.0
A vulnerability classified as critical was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This vulnerability affects the f
4.7MEDIUM
CVE-2024-9903
>= 1.0.0 and <= 1.2.0
A vulnerability classified as critical has been found in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.0. This affects the function f
4.7MEDIUM
CVE-2024-9856
all versions
A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been rated as problematic. Affected by this issue is s
2.4LOW
CVE-2024-9855
all versions
A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been declared as critical. Affected by this vulnerabil
4.7MEDIUM
CVE-2023-5020
all versions
A vulnerability, which was classified as critical, has been found in 07FLY CRM V2. This issue affects some unknown processing of t
7.3HIGH
CVE-2023-3058
<= 1.2.0
A vulnerability was found in 07FLY CRM up to 1.2.0. It has been declared as problematic. This vulnerability affects unknown code o
3.5LOW
CVE-2023-27897
all versions
In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote
6.0MEDIUM
CVE-2021-33676
all versions
A missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privile
7.2HIGH
CVE-2018-2380
all versions
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by
6.6MEDIUM
CVE-2017-15296
all versions
The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.
8.8HIGH
CVE-2017-15294
all versions
The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.
6.1MEDIUM
CVE-2015-3980
all versions
SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL comm
CVE-2015-3979
all versions
Unspecified vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary code via u
CVE-2014-8669
all versions
The SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code via unspec
CVE-2014-1962
all versions
Gwsync in SAP CRM 7.02 EHP 2 allows remote attackers to obtain sensitive information via unspecified vectors, related to an XML Ex
CVE-2013-7095
all versions
The XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack vectors rela
threatengine.sh