PT-2018-15497 · Sap · Sap Basis+1

Published

2018-01-09

·

Updated

2018-01-29

·

CVE-2018-2363

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP NetWeaver, SAP BASIS versions 7.00 through 7.02 SAP NetWeaver, SAP BASIS versions 7.10 through 7.11 SAP NetWeaver, SAP BASIS version 7.30 SAP NetWeaver, SAP BASIS version 7.31 SAP NetWeaver, SAP BASIS version 7.40 SAP NetWeaver, SAP BASIS versions 7.50 through 7.52
Description The issue allows a malicious user to execute arbitrary program code, potentially controlling the system's behavior or escalating privileges by executing malicious code without legitimate credentials.
Recommendations For versions 7.00 through 7.02, update to a version outside of this range to mitigate the risk. For versions 7.10 through 7.11, update to a version outside of this range to mitigate the risk. For version 7.30, update to a version outside of this range to mitigate the risk. For version 7.31, update to a version outside of this range to mitigate the risk. For version 7.40, update to a version outside of this range to mitigate the risk. For versions 7.50 through 7.52, update to a version outside of this range to mitigate the risk.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-2363

Affected Products

Sap Basis
Sap Netweaver