{"api_version":"1","generated_at":"2026-07-23T06:04:30+00:00","cve":"CVE-2018-2380","urls":{"html":"https://cve.report/CVE-2018-2380","api":"https://cve.report/api/cve/CVE-2018-2380.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-2380","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-2380"},"summary":{"title":"CVE-2018-2380","description":"SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing \"traverse to parent directory\" are passed through to the file APIs.","state":"PUBLIC","assigner":"cna@sap.com","published_at":"2018-03-01 17:29:00","updated_at":"2018-03-23 16:39:00"},"problem_types":["CWE-22"],"metrics":[],"references":[{"url":"https://github.com/erpscanteam/CVE-2018-2380","name":"https://github.com/erpscanteam/CVE-2018-2380","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"GitHub - erpscanteam/CVE-2018-2380: PoC of Remote Command Execution via Log injection on SAP NetWeaver AS JAVA CRM","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/103001","name":"103001","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"SAP Customer Relationship Management CVE-2018-2380 Directory Traversal Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://launchpad.support.sap.com/#/notes/2547431","name":"https://launchpad.support.sap.com/#/notes/2547431","refsource":"CONFIRM","tags":["Permissions Required"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/44292/","name":"44292","refsource":"EXPLOIT-DB","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"SAP NetWeaver AS JAVA CRM - Log injection Remote Command Execution - Windows remote Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/","name":"https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"SAP Security Patch Day – February 2018 | SAP Blogs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-2380","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-2380","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"2380","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"customer_relationship_management","cpe6":"7.01","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"2380","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"customer_relationship_management","cpe6":"7.02","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"2380","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"customer_relationship_management","cpe6":"7.30","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"2380","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"customer_relationship_management","cpe6":"7.31","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"2380","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"customer_relationship_management","cpe6":"7.33","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"2380","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"customer_relationship_management","cpe6":"7.54","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"2380","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"customer_relationship_management","cpe6":"7.01","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"2380","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"customer_relationship_management","cpe6":"7.02","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"2380","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"customer_relationship_management","cpe6":"7.30","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"2380","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"customer_relationship_management","cpe6":"7.31","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"2380","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"customer_relationship_management","cpe6":"7.33","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"2380","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"customer_relationship_management","cpe6":"7.54","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":{"cve_year":"2018","cve_id":"2380","cve":"CVE-2018-2380","vendorProject":"SAP","product":"Customer Relationship Management (CRM)","vulnerabilityName":"SAP Customer Relationship Management (CRM) Path Traversal Vulnerability","dateAdded":"2021-11-03","shortDescription":"SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users.","requiredAction":"Apply updates per vendor instructions.","dueDate":"2022-05-03","knownRansomwareCampaignUse":"Known","notes":"https://nvd.nist.gov/vuln/detail/CVE-2018-2380","cwes":"CWE-22","catalogVersion":"2026.07.22","updated_at":"2026-07-22 20:07:16"},"epss":{"cve_year":"2018","cve_id":"2380","cve":"CVE-2018-2380","epss":"0.288920000","percentile":"0.979550000","score_date":"2026-07-22","updated_at":"2026-07-23 00:09:33"},"legacy_qids":[{"cve":"CVE-2018-2380","qid":"87471","title":"SAP NetWeaver AS Java Directory Traversal Vulnerability"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cna@sap.com","ID":"CVE-2018-2380","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"SAP CRM","version":{"version_data":[{"version_affected":"=","version_value":"7.01"},{"version_affected":"=","version_value":"7.02"},{"version_affected":"=","version_value":"7.30"},{"version_affected":"=","version_value":"7.31"},{"version_affected":"=","version_value":"7.33"},{"version_affected":"=","version_value":"7.54"}]}}]},"vendor_name":"SAP SE"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing \"traverse to parent directory\" are passed through to the file APIs."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Directory/Path Traversal"}]}]},"references":{"reference_data":[{"name":"https://github.com/erpscanteam/CVE-2018-2380","refsource":"MISC","url":"https://github.com/erpscanteam/CVE-2018-2380"},{"name":"44292","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/44292/"},{"name":"https://launchpad.support.sap.com/#/notes/2547431","refsource":"CONFIRM","url":"https://launchpad.support.sap.com/#/notes/2547431"},{"name":"103001","refsource":"BID","url":"http://www.securityfocus.com/bid/103001"},{"name":"https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/","refsource":"CONFIRM","url":"https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/"}]}},"nvd":{"publishedDate":"2018-03-01 17:29:00","lastModifiedDate":"2018-03-23 16:39:00","problem_types":["CWE-22"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW","baseScore":6.6,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.3,"impactScore":3.7},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sap:customer_relationship_management:7.01:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sap:customer_relationship_management:7.02:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sap:customer_relationship_management:7.30:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sap:customer_relationship_management:7.31:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sap:customer_relationship_management:7.33:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sap:customer_relationship_management:7.54:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"2380","Ordinal":"117935","Title":"CVE-2018-2380","CVE":"CVE-2018-2380","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"2380","Ordinal":"1","NoteData":"SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing \"traverse to parent directory\" are passed through to the file APIs.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"2380","Ordinal":"2","NoteData":"2018-03-01","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"2380","Ordinal":"3","NoteData":"2018-03-17","Type":"Other","Title":"Modified"}]}}}