← Vulnerability feed

Vulnerability record · CVE-2013-7095 · published 13 December 2013

CVE-2013-7095: Sap customer relationship management vulnerability

Sap · Customer Relationship Management

The XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack vectors related to an XML External Entity (XXE) issue.

10.0 CVSS 2.0 High EPSS 2.1% · top 19.4%
10.0CVSS 2.0 base score
2.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References
17 Jun 2026Last modified by NVD

Description

The XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack vectors related to an XML External Entity (XXE) issue.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-7095 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.6CVE-2018-2380SAP CRM path traversal in user-supplied path validationSAP CRM versions 7.01, 7.02, 7.30, 7.31, 7.33 and 7.54 fail to properly validate user-supplied path information, allowing parent-directory traversal …KEVEPSS 29%analysed10.0CVE-2014-8669Sap customer relationship management code injection vulnerabilityThe SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code via unspecified vectors.EPSS 5.5%8.8CVE-2017-15296Sap customer relationship management cross-site request forgery vulnerabilityThe Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.EPSS 0.55%7.5CVE-2015-3980Sap customer relationship management sql injection vulnerabilitySQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecifie…EPSS 1.4%7.5CVE-2015-3979Sap customer relationship management vulnerabilityUnspecified vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary code via unknown vectors, aka…EPSS 2.4%7.2CVE-2021-33676Sap customer relationship management missing authorization vulnerabilityA missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privileges to compromise c…EPSS 0.91%6.3CVE-2023-27897Sap customer relationship management code injection vulnerabilityIn SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authoriz…EPSS 0.65%6.1CVE-2017-15294Sap customer relationship management cross-site scripting vulnerabilityThe Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.EPSS 0.98%

Source: NIST National Vulnerability Database (record CVE-2013-7095), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.