CVE-2018-2468

HIGH

SAP Adaptive Server Enterprise 15.7 and 16.0 - Unauthorized Information Access

Title source: llm
STIX 2.1

Description

Under certain conditions the backup server in SAP Adaptive Server Enterprise (ASE), versions 15.7 and 16.0, allows an attacker to access information which would otherwise be restricted.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/105527
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2678615

Scores

CVSS v3 7.5
EPSS 0.0033
EPSS Percentile 55.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

Status published
Products (2)
sap/adaptive_server_enterprise 15.7
sap/adaptive_server_enterprise 16.0
Published Oct 09, 2018
Tracked Since Feb 18, 2026