CVE-2018-2380
SAP Customer Relationship Management (CRM) Path Traversal Vulnerability
Severity Score
6.6
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
Yes
*KEV
Decision
-
*SSVC
Descriptions
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
SAP CRM 7.01, 7.02, 7.30, 7.31, 7.33 y 7.54 permite que un atacante explote la validaciĆ³n insuficiente de la informaciĆ³n de ruta proporcionada por los usuarios, por lo que los caracteres que representan "salto al directorio padre" se pasan a las API de archivo.
SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2017-12-15 CVE Reserved
- 2018-03-01 CVE Published
- 2021-11-03 Exploited in Wild
- 2022-05-03 KEV Due Date
- 2024-06-04 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/103001 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/44292 | 2024-08-05 | |
https://github.com/erpscanteam/CVE-2018-2380 | 2024-08-05 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018 | 2018-03-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Sap Search vendor "Sap" | Customer Relationship Management Search vendor "Sap" for product "Customer Relationship Management" | 7.01 Search vendor "Sap" for product "Customer Relationship Management" and version "7.01" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Customer Relationship Management Search vendor "Sap" for product "Customer Relationship Management" | 7.02 Search vendor "Sap" for product "Customer Relationship Management" and version "7.02" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Customer Relationship Management Search vendor "Sap" for product "Customer Relationship Management" | 7.30 Search vendor "Sap" for product "Customer Relationship Management" and version "7.30" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Customer Relationship Management Search vendor "Sap" for product "Customer Relationship Management" | 7.31 Search vendor "Sap" for product "Customer Relationship Management" and version "7.31" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Customer Relationship Management Search vendor "Sap" for product "Customer Relationship Management" | 7.33 Search vendor "Sap" for product "Customer Relationship Management" and version "7.33" | - |
Affected
| ||||||
Sap Search vendor "Sap" | Customer Relationship Management Search vendor "Sap" for product "Customer Relationship Management" | 7.54 Search vendor "Sap" for product "Customer Relationship Management" and version "7.54" | - |
Affected
|