CVE-2018-2380
בינונית 6.6 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- SAP Customer Relationship Management (CRM) Path Traversal Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
מדדים
- CVSS 3.1
-
6.6 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L - EPSS — סבירות ניצול
- 29% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-22
מוצרים מושפעים
sap: customer relationship management
קישורים
- https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/ Vendor Advisory
- https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/ Vendor Advisory
- https://github.com/erpscanteam/CVE-2018-2380 ExploitThird Party Advisory
- https://www.exploit-db.com/exploits/44292/ ExploitThird Party AdvisoryVDB Entry
- https://github.com/erpscanteam/CVE-2018-2380 ExploitThird Party Advisory
- https://www.exploit-db.com/exploits/44292/ ExploitThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/103001 Broken LinkThird Party AdvisoryVDB Entry
- https://launchpad.support.sap.com/#/notes/2547431 Permissions Required
- http://www.securityfocus.com/bid/103001 Broken LinkThird Party AdvisoryVDB Entry
- https://launchpad.support.sap.com/#/notes/2547431 Permissions Required