PT-2018-15538 · Sap · Sap Cloud Platform
Published
2018-04-10
·
Updated
2019-10-09
·
CVE-2018-2409
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP Cloud Platform version 2.0
Description
The issue concerns improper session management in SAP Cloud Platform 2.0, specifically affecting the Connectivity Service and Cloud Connector. This can lead to unauthorized access to or modification of other users' data when using applications built on top of the platform.
Recommendations
For SAP Cloud Platform version 2.0, consider implementing proper session management controls to prevent unauthorized data access or modification. As a temporary workaround, restrict access to sensitive data and applications built on the platform until a proper fix is applied. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Cloud Platform