{"api_version":"1","generated_at":"2026-07-23T08:53:29+00:00","cve":"CVE-2018-2366","urls":{"html":"https://cve.report/CVE-2018-2366","api":"https://cve.report/api/cve/CVE-2018-2366.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-2366","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-2366"},"summary":{"title":"CVE-2018-2366","description":"SAP Business Process Automation (BPA) By Redwood, 9.0, 9.1, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs.","state":"PUBLIC","assigner":"cna@sap.com","published_at":"2018-03-14 19:29:00","updated_at":"2019-10-09 23:40:00"},"problem_types":["CWE-22"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/103371","name":"103371","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"REDWOOD Business Process Automation CVE-2018-2366 Directory Traversal Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://launchpad.support.sap.com/#/notes/2555667","name":"https://launchpad.support.sap.com/#/notes/2555667","refsource":"CONFIRM","tags":["Permissions Required"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://blogs.sap.com/2018/03/13/sap-security-patch-day-march-2018/","name":"https://blogs.sap.com/2018/03/13/sap-security-patch-day-march-2018/","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"SAP Security Patch Day – March 2018 | SAP Blogs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-2366","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-2366","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"2366","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redwood","cpe5":"sap_business_process_automation","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"2366","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redwood","cpe5":"sap_business_process_automation","cpe6":"9.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"2366","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redwood","cpe5":"sap_business_process_automation","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"2366","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"redwood","cpe5":"sap_business_process_automation","cpe6":"9.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cna@sap.com","ID":"CVE-2018-2366","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"SAP Business Process Automation (BPA) By Redwood","version":{"version_data":[{"version_affected":"=","version_value":"9.0"},{"version_affected":"=","version_value":"9.1"}]}}]},"vendor_name":"SAP SE"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SAP Business Process Automation (BPA) By Redwood, 9.0, 9.1, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs."}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.0"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Directory Traversal)"}]}]},"references":{"reference_data":[{"name":"103371","refsource":"BID","url":"http://www.securityfocus.com/bid/103371"},{"name":"https://blogs.sap.com/2018/03/13/sap-security-patch-day-march-2018/","refsource":"CONFIRM","url":"https://blogs.sap.com/2018/03/13/sap-security-patch-day-march-2018/"},{"name":"https://launchpad.support.sap.com/#/notes/2555667","refsource":"CONFIRM","url":"https://launchpad.support.sap.com/#/notes/2555667"}]}},"nvd":{"publishedDate":"2018-03-14 19:29:00","lastModifiedDate":"2019-10-09 23:40:00","problem_types":["CWE-22"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:redwood:sap_business_process_automation:9.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:redwood:sap_business_process_automation:9.1:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"2366","Ordinal":"117921","Title":"CVE-2018-2366","CVE":"CVE-2018-2366","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"2366","Ordinal":"1","NoteData":"SAP Business Process Automation (BPA) By Redwood, 9.0, 9.1, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"2366","Ordinal":"2","NoteData":"2018-03-14","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"2366","Ordinal":"3","NoteData":"2018-03-15","Type":"Other","Title":"Modified"}]}}}