CVE-2018-2380

Published Mar 1, 2018

Last updated 3 days ago

Overview

Description
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
Source
cna@sap.com
NVD status
Modified

Risk scores

CVSS 3.0

Type
Primary
Base score
6.6
Impact score
3.7
Exploitability score
2.3
Vector string
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
Severity
MEDIUM

CVSS 2.0

Type
Primary
Base score
6.5
Impact score
6.4
Exploitability score
8
Vector string
AV:N/AC:L/Au:S/C:P/I:P/A:P

Known exploits

Data from CISA

Vulnerability name
SAP Customer Relationship Management (CRM) Path Traversal Vulnerability
Exploit added on
Nov 3, 2021
Exploit action due
May 3, 2022
Required action
Apply updates per vendor instructions.

Weaknesses

nvd@nist.gov
CWE-22

Social media

Hype score
Not currently trending

Configurations