CVE-2018-2380
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus...
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- December 15, 2017
- Published Date
- March 01, 2018
- Last Updated
- January 29, 2025
- Vendor
- SAP SE
- Product
- SAP CRM
- Description
- SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
- Tags
- Exploitation
- active
- Technical Impact
- partial
CVSS Scores
CVSS v3.1
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
CVSS v2.0
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P
SSVC Information
References
Known Exploited Vulnerability Information
Source | Added Date |
---|---|
CISA | 2021-11-03 00:00:00 UTC |
Potential Proof of Concepts
Warning: These PoCs have not been tested and could contain malware. Use at your own risk.
erpscanteam/CVE-2018-2380
Type: github • Created: 2018-03-14 09:20:21 UTC • Stars: 52
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Proof of Concept Exploit Available
-
Exploit Used in Malware
-
Added to KEVIntel