SAPCVE-2026-44768
SAP CRM (WebClient UI): attacker could inject
Medium4.1CVE-2026-44768 · Published Jul 14, 2026
SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the application due to the absence of a Content Security Policy (CSP) configuration for certain restrictive directives. This vulnerability has a low impact on the integrity of the application. Confidentiality and availability are not impacted.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| SAP CRM (WebClient UI) Product | <= S4FND 104 | No fix yet |
| <= 105 | No fix yet | |
| <= 106 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-15
More SAP advisories
All SAP| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 14 | SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented... | Critical9.1 | No fix yet |
| Jul 14 | SAP @ui5/webcomponents-base: clickjacking | Medium6.1 | No fix yet |
| Jul 14 | SAP S/4HANA Project Management (PPM-PRO): SQL injection | Medium5.5 | No fix yet |
| Jul 14 | SAP S/4 HANA (Create Single Payment): missing authorization | Medium4.3 | No fix yet |
| Jul 14 | SAP S/4HANA (Draft operation): privilege escalation | Medium4.3 | No fix yet |
| Jul 14 | SAP Change and Transport System Attach Tool (ctsattach): unsafe deserialization | High7.6 | No fix yet |