← Vulnerability feed

Vulnerability record · CVE-2015-3980 · published 12 May 2015

CVE-2015-3980: Sap customer relationship management sql injection vulnerability

Sap · Customer Relationship Management

SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2097534.

7.5 CVSS 2.0 High EPSS 1.4% · top 28.0% CWE-89 · SQL injection
7.5CVSS 2.0 base score
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

SQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2097534.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-3980 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.6CVE-2018-2380SAP CRM path traversal in user-supplied path validationSAP CRM versions 7.01, 7.02, 7.30, 7.31, 7.33 and 7.54 fail to properly validate user-supplied path information, allowing parent-directory traversal …KEVEPSS 29%analysed10.0CVE-2014-8669Sap customer relationship management code injection vulnerabilityThe SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code via unspecified vectors.EPSS 5.5%10.0CVE-2013-7095Sap customer relationship management vulnerabilityThe XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack vectors related to an XML Exter…EPSS 2.1%8.8CVE-2017-15296Sap customer relationship management cross-site request forgery vulnerabilityThe Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.EPSS 0.55%7.5CVE-2015-3979Sap customer relationship management vulnerabilityUnspecified vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary code via unknown vectors, aka…EPSS 2.4%7.2CVE-2021-33676Sap customer relationship management missing authorization vulnerabilityA missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privileges to compromise c…EPSS 0.91%6.3CVE-2023-27897Sap customer relationship management code injection vulnerabilityIn SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authoriz…EPSS 0.65%6.1CVE-2017-15294Sap customer relationship management cross-site scripting vulnerabilityThe Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.EPSS 0.98%

Source: NIST National Vulnerability Database (record CVE-2015-3980), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.