Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 14 Jul 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the application due to the absence of a Content Security Policy (CSP) configuration for certain restrictive directives. This vulnerability has a low impact on the integrity of the application. Confidentiality and availability are not impacted. | |
| Title | Security misconfiguration in SAP CRM (WebClient UI) | |
| Weaknesses | CWE-15 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: sap
Published:
Updated: 2026-07-14T12:48:49.816Z
Reserved: 2026-05-07T18:39:44.147Z
Link: CVE-2026-44768
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-29T06:45:04Z
-
CWE-15
External Control of System or Configuration Setting