← לוח פגיעויות

CVE-2018-2380

בינונית 6.6 מנוצלת בשטח (KEV) בשימוש בכופרה

ניצול פעיל מאומת — קטלוג CISA KEV

שם
SAP Customer Relationship Management (CRM) Path Traversal Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
Apply updates per vendor instructions.

תיאור (מקור, אנגלית)

SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.

מדדים

CVSS 3.1
6.6 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
EPSS — סבירות ניצול
29% (אחוזון 100) נכון ל-25/7/2026
CWE
CWE-22

מוצרים מושפעים

sap: customer relationship management

קישורים