CVE-2019-0368: SAP Customer Relationship Management Bbpcrm
Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.
SAP Customer Relationship Management (Email Management), versions: S4CRM before 1.0 and 2.0, BBPCRM before 7.0, 7.01, 7.02, 7.12, 7.13 and 7.14, does not sufficiently encode user-controlled inputs within the mail client resulting in Cross-Site Scripting vulnerability.
Affected products
- SAP Customer Relationship Management Bbpcrm: version 7.0 only; version 7.01 only; version 7.02 only; version 7.12 only; version 7.13 only; version 7.14 only
- SAP Customer Relationship Management s4crm: version 1.0 only; version 2.0 only
Published 2019-10-08. Last modified 2026-06-17.