S4fnd
This hub aggregates every CVE we track for S4fnd, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.
5
CVEs tracked
0
Critical
0
High
0
In CISA KEV
Severity distribution
MEDIUM5
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 5 most recently published vulnerabilities affecting S4fnd.
- CVE-2023-29188Cross-Site Scripting (XSS) vulnerability in SAP CRM WebClient UI5.4
- CVE-2023-24525SAP CRM WebClient UI - versions WEBCUIF 748, 800, 801, S4FND 102, 103, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. On successful exp...4.3
- CVE-2019-0245SAP CRM WebClient UI (fixed in SAPSCORE 1.12; S4FND 1.02; WEBCUIF 7.31, 7.46, 7.47, 7.48, 8.0, 8.01) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vul...5.4
- CVE-2019-0244SAP CRM WebClient UI (fixed in SAPSCORE 1.12; S4FND 1.02; WEBCUIF 7.31, 7.46, 7.47, 7.48, 8.0, 8.01) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vul...5.4
- CVE-2018-2364SAP CRM WebClient UI 7.01, 7.31, 7.46, 7.47, 7.48, 8.00, 8.01, S4FND 1.02, does not sufficiently validate and/or encode hidden fields, resulting in Cross-Site Scripting (XSS) vulnerability.6.1
Product normalization is registry-driven with AI assist and human review. How it works