launchpad.support.sap.com
https://launchpad.support.sap.com/ CVE-2018-2490
HIGH
Record summary
CVE-2018-2490 has a selected CVSS score of 7.8 (high).
Description
The broadcast messages received by SAP Fiori Client are not protected by permissions. SAP Fiori Client version 1.11.5 in Google Play store addresses these issues and users must update to that version.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
SAP Fiori ClientBrowse SAP / SAP Fiori Client | CVE List | < 1.11.5 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-2490 wiki.scn.sap.com
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=503809832