CVE-2018-2380

MEDIUM KEV RANSOMWARE

SAP CRM 7.01-7.02, 7.30-7.31, 7.33, 7.54 - Path Traversal

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2018-2380 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021, with confirmed use in ransomware campaigns. EIP tracks 3 public exploits from researchers including erp scan team, erpscanteam, The-Real-TechLord.

AI-analyzed exploit summary This exploit leverages a log injection vulnerability in SAP CRM to achieve remote command execution by manipulating log file paths and injecting a JSP shell. It requires valid credentials and interacts with the SAP CRM admin interface to deploy the payload.

Description

SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.

Exploits (3)

exploitdb WORKING POC
by erp scan team · pythonremotewindows
https://www.exploit-db.com/exploits/44292

This exploit leverages a log injection vulnerability in SAP CRM to achieve remote command execution by manipulating log file paths and injecting a JSP shell. It requires valid credentials and interacts with the SAP CRM admin interface to deploy the payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SAP CRM (specific version not specified, but CVE-2018-2380 affects SAP CRM 7.0)
Auth required
Prerequisites: Valid SAP CRM administrator credentials · Network access to the SAP CRM admin interface · SAP CRM version vulnerable to CVE-2018-2380
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 51 stars
by erpscanteam · remote
https://github.com/erpscanteam/CVE-2018-2380

This PoC exploits CVE-2018-2380, a log injection vulnerability in SAP NetWeaver AS JAVA CRM, to achieve remote command execution by injecting a JSP shell into the log file path and then accessing it to execute arbitrary commands.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SAP NetWeaver AS JAVA CRM
Auth required
Prerequisites: Valid SAP administrator credentials · Network access to the SAP NetWeaver AS Java port · SAP SID
devstral-2 · analyzed Feb 16, 2026 Full analysis →
gitlab WORKING POC
by The-Real-TechLord · remote-auth
https://gitlab.com/The-Real-TechLord/CVE-2018-2380

This repository contains a functional Python exploit for CVE-2018-2380, which achieves remote command execution (RCE) on SAP NetWeaver AS JAVA CRM via log injection. The exploit authenticates to the SAP portal, manipulates log file paths to upload a malicious JSP shell, and restores the original log path.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SAP NetWeaver AS JAVA CRM
Auth required
Prerequisites: valid SAP administrator credentials · network access to SAP NetWeaver AS JAVA CRM · SAP SID
devstral-2 · analyzed Feb 23, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit, Third Party Advisory x_refsource_misc
https://github.com/erpscanteam/CVE-2018-2380
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/44292/
Permissions Required x_refsource_confirm
https://launchpad.support.sap.com/#/notes/2547431
Broken Link, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/103001

Scores

CVSS v3 6.6
EPSS 0.2923
EPSS Percentile 97.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact partial

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-04-08
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2018-14235
Ransomware Use Confirmed
CWE
CWE-22
Status published
Products (6)
sap/customer_relationship_management 7.01
sap/customer_relationship_management 7.02
sap/customer_relationship_management 7.30
sap/customer_relationship_management 7.31
sap/customer_relationship_management 7.33
sap/customer_relationship_management 7.54
Published Mar 01, 2018
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026