PT-2018-15593 · Sap · Sap Netweaver Knowledge Management
Publicado
2018-11-13
·
Atualizado
2019-02-01
·
CVE-2018-2477
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver Knowledge Management (XMLForms) versions 7.30 through 7.50
Description
The issue arises from insufficient validation of an XML document accepted from an untrusted source. This could potentially lead to security issues, but specific details about exploitation or affected devices are not provided.
Recommendations
For versions 7.30 through 7.50, update to a version that includes the fix for this issue, as the current versions do not sufficiently validate XML documents from untrusted sources.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Sap Netweaver Knowledge Management