CVE-2019-0368: SAP Customer Relationship Management Bbpcrm

Medium severity, CVSS 5.4. EPSS: 0.5% chance of exploitation in the next 30 days.

SAP Customer Relationship Management (Email Management), versions: S4CRM before 1.0 and 2.0, BBPCRM before 7.0, 7.01, 7.02, 7.12, 7.13 and 7.14, does not sufficiently encode user-controlled inputs within the mail client resulting in Cross-Site Scripting vulnerability.

Affected products

  • SAP Customer Relationship Management Bbpcrm: version 7.0 only; version 7.01 only; version 7.02 only; version 7.12 only; version 7.13 only; version 7.14 only
  • SAP Customer Relationship Management s4crm: version 1.0 only; version 2.0 only

Published 2019-10-08. Last modified 2026-06-17.