CVE-2018-2380
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- December 15, 2017
- Published Date
- March 01, 2018
- Last Updated
- January 29, 2025
- Vendor
- SAP SE
- Product
- SAP CRM
- Description
- SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
CVSS Scores
SSVC Information
- Exploitation
- active
- Technical Impact
- partial
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2021-11-03 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
erpscanteam/CVE-2018-2380
Type: github • Created: 2018-03-14 09:20:21 UTC • Stars: 52
PoC of Remote Command Execution via Log injection on SAP NetWeaver AS JAVA CRM