CVE-2019-0245: SAP Customer Relationship Management Webclient UI

Medium severity, CVSS 5.4. EPSS: 0.8% chance of exploitation in the next 30 days.

SAP CRM WebClient UI (fixed in SAPSCORE 1.12; S4FND 1.02; WEBCUIF 7.31, 7.46, 7.47, 7.48, 8.0, 8.01) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

Affected products

  • SAP Customer Relationship Management Webclient UI: version 7.31 only; version 7.46 only; version 7.47 only; version 7.48 only; version 8.00 only; version 8.01 only
  • SAP s4fnd: version 1.02 only
  • SAP Sapscore: version 1.12 only

Published 2019-01-08. Last modified 2026-06-17.