PT-2018-15571 · Sap · Sap Srm Mdm Catalog
Publicado
2018-08-14
·
Atualizado
2018-10-11
·
CVE-2018-2449
CVSS v3.1
8.6
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H |
Name of the Vulnerable Software and Affected Versions
SAP SRM MDM Catalog versions 3.73, 7.31, 7.32
Description
The issue concerns an unauthenticated functionality in the import feature that fails to perform authentication checks for valid repository users. This can be exploited on Windows machines to perform SMB relaying.
Recommendations
For SAP SRM MDM Catalog version 3.73, update to a version that includes the fix for this issue.
For SAP SRM MDM Catalog version 7.31, update to a version that includes the fix for this issue.
For SAP SRM MDM Catalog version 7.32, update to a version that includes the fix for this issue.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sap Srm Mdm Catalog