PT-2017-3777 · Sap · Sap Fiori Client

Published

2017-12-15

·

Updated

2019-10-03

·

CVE-2018-2485

CVSS v3.1

7.7

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SAP Fiori Client versions prior to 1.11.5
Description The issue is related to insufficient access control in the SAP Fiori Client mobile environment, allowing a remote attacker to gain unauthorized access to protected information and execute arbitrary JavaScript code. This can include reading and writing of information and calling device-specific JavaScript APIs in the application.
Recommendations For versions prior to 1.11.5, update to SAP Fiori Client version 1.11.5 to address the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01224
CVE-2018-2485

Affected Products

Sap Fiori Client