← All CVEs

CVE-2018-2380

medium · 6.6Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2021-11-03Remediation due 2022-05-03

SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.

6.6
CVSS
28.9%
EPSS (exploit prob.)
98th
EPSS percentile
2018-03-01
Published

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

Weaknesses

CWE-22

Affected products

VendorProductAffected versions
sapcustomer_relationship_management7.01
sapcustomer_relationship_management7.02
sapcustomer_relationship_management7.30
sapcustomer_relationship_management7.31
sapcustomer_relationship_management7.33
sapcustomer_relationship_management7.54

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-2380