PT-2018-15538 · Sap · Sap Cloud Platform

Published

2018-04-10

·

Updated

2019-10-09

·

CVE-2018-2409

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP Cloud Platform version 2.0
Description The issue concerns improper session management in SAP Cloud Platform 2.0, specifically affecting the Connectivity Service and Cloud Connector. This can lead to unauthorized access to or modification of other users' data when using applications built on top of the platform.
Recommendations For SAP Cloud Platform version 2.0, consider implementing proper session management controls to prevent unauthorized data access or modification. As a temporary workaround, restrict access to sensitive data and applications built on the platform until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-2409

Affected Products

Sap Cloud Platform