CVE-2018-2363

HIGH

SAP NetWeaver 7.00-7.02, 7.10-7.11, 7.30-7.31, 7.40, 7.50-7.52 - Unauthenticated Remote Code Execution

Title source: llm
STIX 2.1

Description

SAP NetWeaver, SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, contains code that allows you to execute arbitrary program code of the user's choice. A malicious user can therefore control the behaviour of the system or can potentially escalate privileges by executing malicious code without legitimate credentials.

References (4)

Core 4
Core References
Permissions Required x_refsource_confirm
https://launchpad.support.sap.com/#/notes/1906212
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/102449
Permissions Required x_refsource_confirm
https://launchpad.support.sap.com/#/notes/2525392

Scores

CVSS v3 8.8
EPSS 0.0074
EPSS Percentile 73.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (5)
sap/business_application_software_integrated_solution 7.30
sap/business_application_software_integrated_solution 7.31
sap/business_application_software_integrated_solution 7.40
sap/business_application_software_integrated_solution 7.00 - 7.02
sap/netweaver
Published Jan 09, 2018
Tracked Since Feb 18, 2026