← Vulnerability feed

Vulnerability record · CVE-2014-8669 · published 6 November 2014

CVE-2014-8669: Sap customer relationship management code injection vulnerability

Sap · Customer Relationship Management

The SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code via unspecified vectors.

10.0 CVSS 2.0 High EPSS 5.5% · top 7.5% CWE-94 · Code injection
10.0CVSS 2.0 base score
5.5%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

The SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code via unspecified vectors.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-8669 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.6CVE-2018-2380SAP CRM path traversal in user-supplied path validationSAP CRM versions 7.01, 7.02, 7.30, 7.31, 7.33 and 7.54 fail to properly validate user-supplied path information, allowing parent-directory traversal …KEVEPSS 29%analysed10.0CVE-2013-7095Sap customer relationship management vulnerabilityThe XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack vectors related to an XML Exter…EPSS 2.1%8.8CVE-2017-15296Sap customer relationship management cross-site request forgery vulnerabilityThe Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.EPSS 0.55%7.5CVE-2015-3980Sap customer relationship management sql injection vulnerabilitySQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecifie…EPSS 1.4%7.5CVE-2015-3979Sap customer relationship management vulnerabilityUnspecified vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary code via unknown vectors, aka…EPSS 2.4%7.2CVE-2021-33676Sap customer relationship management missing authorization vulnerabilityA missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privileges to compromise c…EPSS 0.91%6.3CVE-2023-27897Sap customer relationship management code injection vulnerabilityIn SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authoriz…EPSS 0.65%6.1CVE-2017-15294Sap customer relationship management cross-site scripting vulnerabilityThe Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.EPSS 0.98%

Source: NIST National Vulnerability Database (record CVE-2014-8669), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.