CVE-2018-2380
medium · 6.6Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply updates per vendor instructions.
Added 2021-11-03Remediation due 2022-05-03
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
6.6
CVSS
28.9%
EPSS (exploit prob.)
98th
EPSS percentile
2018-03-01
Published
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Weaknesses
CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| sap | customer_relationship_management | 7.01 |
| sap | customer_relationship_management | 7.02 |
| sap | customer_relationship_management | 7.30 |
| sap | customer_relationship_management | 7.31 |
| sap | customer_relationship_management | 7.33 |
| sap | customer_relationship_management | 7.54 |
Check a specific version with /api/v1/cve/match.
References
- http://www.securityfocus.com/bid/103001
- https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/
- https://github.com/erpscanteam/CVE-2018-2380
- https://launchpad.support.sap.com/#/notes/2547431
- https://www.exploit-db.com/exploits/44292/
- http://www.securityfocus.com/bid/103001
- https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/
- https://github.com/erpscanteam/CVE-2018-2380
- https://launchpad.support.sap.com/#/notes/2547431
- https://www.exploit-db.com/exploits/44292/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-2380
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-2380