{"api_version":"1","generated_at":"2026-07-23T08:26:23+00:00","cve":"CVE-2018-2409","urls":{"html":"https://cve.report/CVE-2018-2409","api":"https://cve.report/api/cve/CVE-2018-2409.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-2409","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-2409"},"summary":{"title":"CVE-2018-2409","description":"Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud Connector). Under certain conditions, data of some other user may be shown or modified when using an application built on top of SAP Cloud Platform.","state":"PUBLIC","assigner":"cna@sap.com","published_at":"2018-04-10 15:29:00","updated_at":"2019-10-09 23:40:00"},"problem_types":["CWE-384"],"metrics":[],"references":[{"url":"https://launchpad.support.sap.com/#/notes/2614141","name":"https://launchpad.support.sap.com/#/notes/2614141","refsource":"MISC","tags":["Permissions Required"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/103702","name":"103702","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"SAP Cloud Platform Connector CVE-2018-2409 Unspecified Session Fixation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://blogs.sap.com/2018/04/10/sap-security-patch-day-april-2018/","name":"https://blogs.sap.com/2018/04/10/sap-security-patch-day-april-2018/","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"SAP Security Patch Day – April 2018 | SAP Blogs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-2409","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-2409","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"2409","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"cloud_platform","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"2409","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sap","cpe5":"cloud_platform","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cna@sap.com","ID":"CVE-2018-2409","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"SAP Cloud Platform Connector","version":{"version_data":[{"version_affected":"=","version_value":"2.0"}]}}]},"vendor_name":"SAP SE"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud Connector). Under certain conditions, data of some other user may be shown or modified when using an application built on top of SAP Cloud Platform."}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":6.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","version":"3.0"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Other"}]}]},"references":{"reference_data":[{"name":"103702","refsource":"BID","url":"http://www.securityfocus.com/bid/103702"},{"name":"https://blogs.sap.com/2018/04/10/sap-security-patch-day-april-2018/","refsource":"CONFIRM","url":"https://blogs.sap.com/2018/04/10/sap-security-patch-day-april-2018/"},{"name":"https://launchpad.support.sap.com/#/notes/2614141","refsource":"MISC","url":"https://launchpad.support.sap.com/#/notes/2614141"}]}},"nvd":{"publishedDate":"2018-04-10 15:29:00","lastModifiedDate":"2019-10-09 23:40:00","problem_types":["CWE-384"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:sap:cloud_platform:2.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"2409","Ordinal":"117964","Title":"CVE-2018-2409","CVE":"CVE-2018-2409","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"2409","Ordinal":"1","NoteData":"Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud Connector). Under certain conditions, data of some other user may be shown or modified when using an application built on top of SAP Cloud Platform.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"2409","Ordinal":"2","NoteData":"2018-04-10","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"2409","Ordinal":"3","NoteData":"2018-04-11","Type":"Other","Title":"Modified"}]}}}