First published: Mon Oct 16 2017(Updated: )
The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Customer Relationship Management | =700 | |
SAP Customer Relationship Management | =701 | |
SAP Customer Relationship Management | =702 | |
SAP Customer Relationship Management | =730 | |
SAP Customer Relationship Management | =731 | |
SAP Customer Relationship Management | =732 | |
SAP Customer Relationship Management | =733 | |
SAP Customer Relationship Management | =754 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15296 presents a medium severity due to its CSRF vulnerability in SAP CRM.
To remediate CVE-2017-15296, apply SAP Security Note 2478964 and implement the recommended patches.
CVE-2017-15296 affects SAP CRM versions 700, 701, 702, 730, 731, 732, 733, and 754.
CVE-2017-15296 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
The vulnerability exists specifically within the Java component of SAP Customer Relationship Management.