SAP Customer Relationship Management CVE-2018-2380 Directory Traversal Vulnerability
BID:103001
CVE-2018-2380 |Info
SAP Customer Relationship Management CVE-2018-2380 Directory Traversal Vulnerability
| Bugtraq ID: | 103001 |
| Class: | Input Validation Error |
| CVE: |
CVE-2018-2380 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 13 2018 12:00AM |
| Updated: | Feb 13 2018 12:00AM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
SAP Customer Relationship Management 7.54 SAP Customer Relationship Management 7.33 SAP Customer Relationship Management 7.31 SAP Customer Relationship Management 7.30 SAP Customer Relationship Management 7.02 SAP Customer Relationship Management 7.01 |
| Not Vulnerable: | |
Discussion
SAP Customer Relationship Management CVE-2018-2380 Directory Traversal Vulnerability
SAP Customer Relationship Management (CRM) is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to retrieve arbitrary files in the context of the application. This may aid in further attacks.
SAP Customer Relationship Management (CRM) is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input.
Remote attackers can use specially crafted requests with directory-traversal sequences ('../') to retrieve arbitrary files in the context of the application. This may aid in further attacks.
Exploit / POC
SAP Customer Relationship Management CVE-2018-2380 Directory Traversal Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
SAP Customer Relationship Management CVE-2018-2380 Directory Traversal Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
SAP Customer Relationship Management CVE-2018-2380 Directory Traversal Vulnerability
References:
References:
- SAP Homepage (SAP)
- SAP Security Note 2547431 (SAP)
- SAP Security Patch Day �?? February 2018 (SAP)