CVE-2018-2434
Last modified
CVE-2018-2434 is a vulnerability of currently unknown severity. A content spoofing vulnerability in the following components allows to render html pages containing arbitrary plain text content, which might fool an end user: UI add-on for SAP NetWeaver (UI_Infra, 1.0), SAP UI Implementation for Decoupled Innovations (UI_700, 2.0): SAP NetWeaver 7.00 Implementation, SAP User Interface Technology (SAP_UI 7.4, 7.5, 7.51, 7.52). There is little impact as it is not possible to embed active contents such as JavaScript or hyperlinks.. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
A content spoofing vulnerability in the following components allows to render html pages containing arbitrary plain text content, which might fool an end user: UI add-on for SAP NetWeaver (UI_Infra, 1.0), SAP UI Implementation for Decoupled Innovations (UI_700, 2.0): SAP NetWeaver 7.00 Implementation, SAP User Interface Technology (SAP_UI 7.4, 7.5, 7.51, 7.52). There is little impact as it is not possible to embed active contents such as JavaScript or hyperlinks.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver | 7.0 |
| Sap | Ui Infra | 1.0 |
| Sap | User Interface Technology | 7.4 |
| Sap | User Interface Technology | 7.5 |
| Sap | User Interface Technology | 7.51 |
| Sap | User Interface Technology | 7.52 |
References
- http://www.securityfocus.com/bid/105088Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2633180Permissions Required, Vendor Advisory
- http://www.securityfocus.com/bid/105088Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2633180Permissions Required, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-2434?
How severe is CVE-2018-2434?
How do I fix CVE-2018-2434?
Are you affected by CVE-2018-2434?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
