Skip to content
SAPCVE-2026-44768

SAP CRM (WebClient UI): attacker could inject

Medium4.1CVE-2026-44768 · Published Jul 14, 2026

SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the application due to the absence of a Content Security Policy (CSP) configuration for certain restrictive directives. This vulnerability has a low impact on the integrity of the application. Confidentiality and availability are not impacted.

SAP advisory

Affected versions

PackageAffectedFixed in
SAP CRM (WebClient UI)
Product
<= S4FND 104No fix yet
<= 105No fix yet
<= 106No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-15

More SAP advisories

All SAP
Advisory
SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented...
Critical9.1Jul 14
SAP @ui5/webcomponents-base: clickjacking
Medium6.1Jul 14
SAP S/4HANA Project Management (PPM-PRO): SQL injection
Medium5.5Jul 14
SAP S/4 HANA (Create Single Payment): missing authorization
Medium4.3Jul 14
SAP S/4HANA (Draft operation): privilege escalation
Medium4.3Jul 14
SAP Change and Transport System Attach Tool (ctsattach): unsafe deserialization
High7.6Jul 14

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.