CVE-2015-3980: SAP Customer Relationship Management

High severity, CVSS 7.5. EPSS: 1.4% chance of exploitation in the next 30 days.

SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2097534.

Affected products

  • SAP Customer Relationship Management: affected versions not specified

Published 2015-05-12. Last modified 2026-06-17.