CVE-2023-29189: SAP Customer Relationship Management s4fnd

Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.

SAP CRM (WebClient UI) - versions S4FND 102, 103, 104, 105, 106, 107, WEBCUIF, 700, 701, 731, 730, 746, 747, 748, 800, 801, allows an authenticated attacker to modify HTTP verbs used in requests to the web server. This application is exposed over the network and successful exploitation can lead to exposure of form fields

Affected products

  • SAP Customer Relationship Management s4fnd: version 102 only; version 103 only; version 104 only; version 105 only
  • SAP Customer Relationship Management Webclient UI: version 700 only; version 701 only; version 730 only; version 731 only; version 746 only; version 747 only; …

Published 2023-04-11. Last modified 2026-06-17.