SAP Netweaver CVE-2018-2363 Remote Code Injection Vulnerability
BID:102449
CVE-2018-2363 |Info
SAP Netweaver CVE-2018-2363 Remote Code Injection Vulnerability
| Bugtraq ID: | 102449 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-2363 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 09 2018 12:00AM |
| Updated: | Jan 09 2018 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
SAP NetWeaver 7.52 SAP NetWeaver 7.50 SAP NetWeaver 7.40 SAP NetWeaver 7.31 SAP NetWeaver 7.30 SAP NetWeaver 7.11 SAP NetWeaver 7.10 SAP NetWeaver 7.02 SAP NetWeaver 7.01 SAP NetWeaver 7.0 |
| Not Vulnerable: | |
Discussion
SAP Netweaver CVE-2018-2363 Remote Code Injection Vulnerability
SAP Netweaver is prone to a remote code-injection vulnerability.
Successful exploits may allow an attacker to inject and run arbitrary code or obtain sensitive information that may aid in further attacks. Failed exploit attempts may result in a denial-of-service condition.
SAP Netweaver 7.00 through 7.02, 7.50 through 7.52, 7.10, 7.11, 7.30, 7.31, and 7.40 vulnerable.
SAP Netweaver is prone to a remote code-injection vulnerability.
Successful exploits may allow an attacker to inject and run arbitrary code or obtain sensitive information that may aid in further attacks. Failed exploit attempts may result in a denial-of-service condition.
SAP Netweaver 7.00 through 7.02, 7.50 through 7.52, 7.10, 7.11, 7.30, 7.31, and 7.40 vulnerable.
Exploit / POC
SAP Netweaver CVE-2018-2363 Remote Code Injection Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
SAP Netweaver CVE-2018-2363 Remote Code Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
SAP Netweaver CVE-2018-2363 Remote Code Injection Vulnerability
References:
References:
- SAP Homepage (SAP)
- SAP Security Note 2525392 (SAP)
- SAP Security Patch Day �?? January 2018 (sap)