CVE-2013-7095: SAP Customer Relationship Management

High severity, CVSS 10.0. EPSS: 2.1% chance of exploitation in the next 30 days.

The XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack vectors related to an XML External Entity (XXE) issue.

Affected products

  • SAP Customer Relationship Management: version 7.02 only

Published 2013-12-13. Last modified 2026-06-17.