CVE-2018-2366
Summary
| CVE | CVE-2018-2366 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-14 19:29:00 UTC |
| Updated | 2019-10-09 23:40:00 UTC |
| Description | SAP Business Process Automation (BPA) By Redwood, 9.0, 9.1, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Redwood | Sap Business Process Automation | 9.0 | All | All | All |
| Application | Redwood | Sap Business Process Automation | 9.1 | All | All | All |
| Application | Redwood | Sap Business Process Automation | 9.0 | All | All | All |
| Application | Redwood | Sap Business Process Automation | 9.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| REDWOOD Business Process Automation CVE-2018-2366 Directory Traversal Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| launchpad.support.sap.com | CONFIRM | launchpad.support.sap.com | Permissions Required |
| SAP Security Patch Day – March 2018 | SAP Blogs | CONFIRM | blogs.sap.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.