CVE-2017-15296: CSRF
Published Oct 16, 2017
·Updated
The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.
Affected Software
8 affected components
SAP Customer Relationship Management=700
SAP Customer Relationship Management=701
SAP Customer Relationship Management=702
SAP Customer Relationship Management=730
SAP Customer Relationship Management=731
SAP Customer Relationship Management=732
SAP Customer Relationship Management=733
SAP Customer Relationship Management=754
Event History
Oct 16, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15296?
CVE-2017-15296 presents a medium severity due to its CSRF vulnerability in SAP CRM.
2
How do I fix CVE-2017-15296?
To remediate CVE-2017-15296, apply SAP Security Note 2478964 and implement the recommended patches.
3
What versions of SAP CRM are affected by CVE-2017-15296?
CVE-2017-15296 affects SAP CRM versions 700, 701, 702, 730, 731, 732, 733, and 754.
4
What type of vulnerability is CVE-2017-15296?
CVE-2017-15296 is classified as a Cross-Site Request Forgery (CSRF) vulnerability.
5
What components are vulnerable in CVE-2017-15296?
The vulnerability exists specifically within the Java component of SAP Customer Relationship Management.