CVE-2018-2363
Last modified
CVE-2018-2363 is a vulnerability of currently unknown severity. SAP NetWeaver, SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, contains code that allows you to execute arbitrary program code of the user's choice. A malicious user can therefore control the behaviour of the system or can potentially escalate privileges by executing malicious code without legitimate credentials.. EPSS estimates a 1.67% chance of exploitation in the next 30 days.
Description
SAP NetWeaver, SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, contains code that allows you to execute arbitrary program code of the user's choice. A malicious user can therefore control the behaviour of the system or can potentially escalate privileges by executing malicious code without legitimate credentials.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver | All versions |
| Sap | Business Application Software Integrated Solution | >= 7.00, <= 7.02 |
| Sap | Business Application Software Integrated Solution | >= 7.10, <= 7.11 |
| Sap | Business Application Software Integrated Solution | >= 7.50, <= 7.52 |
| Sap | Business Application Software Integrated Solution | 7.30 |
| Sap | Business Application Software Integrated Solution | 7.31 |
| Sap | Business Application Software Integrated Solution | 7.40 |
References
- http://www.securityfocus.com/bid/102449Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/1906212Permissions Required
- https://launchpad.support.sap.com/#/notes/2525392Permissions Required
- http://www.securityfocus.com/bid/102449Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/1906212Permissions Required
- https://launchpad.support.sap.com/#/notes/2525392Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-2363?
How severe is CVE-2018-2363?
How do I fix CVE-2018-2363?
Are you affected by CVE-2018-2363?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
