Executive brief
SAP CRM WebClient UI, a tool used by businesses to manage customer relationships and sales workflows, is missing a security configuration known as a Content Security Policy (CSP). This omission could allow an attacker to trick a user into executing unauthorized scripts within their browser while using the application. While this flaw has a low impact on data integrity and does not allow for data theft or service outages, it could be used to manipulate how the application appears or behaves for the user.
Technical details
SAP CRM WebClient UI (S4FND versions 104, 105, and 106) is vulnerable to script injection due to the absence of restrictive Content Security Policy (CSP) directives. The vulnerability is classified under CWE-15 (External Control of System or Configuration Setting). An attacker with low privileges can exploit this over the network, though it requires user interaction (UI:R) to execute malicious scripts in the victim's browser context. The impact is limited to a low integrity violation (I:L) with no impact on confidentiality or availability. SAP has released security note 3155685 to address this configuration deficiency.
Affected products
- SAP SE CRM WebClient UI (S4FND) 104, 105, 106
Timeline
- 2026-07-14: advisory: Published as part of SAP July 2026 Patch Day