Impact
The vulnerability allows an attacker to embed and run malicious scripts within the SAP CRM WebClient UI because the application lacks a properly configured Content Security Policy. This script injection does not expose confidential data or disrupt availability, but it can tamper with the integrity of the application’s data or user interface. The weakness is identified as an Improper Restriction of Operations (CWE-15).
Affected Systems
SAP SE’s SAP CRM WebClient UI is affected. No specific version information is available, so any deployment of this product should be examined for the missing CSP configuration and remedied accordingly.
Risk and Exploitability
With a CVSS score of 4.1, the severity is considered low. The EPSS score is less than 1%, indicating a very small likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through a web page or component served by the WebClient UI; an attacker with access to the application could supply a malicious script payload via input fields or URLs. Exploitation requires the absence of a restrictive CSP configuration and therefore hinges on the misconfiguration.
OpenCVE Enrichment