CVE Vulnerabilities

CVE-2018-2428

Published: Jun 12, 2018 | Modified: Nov 21, 2024
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Under certain conditions SAP UI5 Handler allows an attacker to access information which would otherwise be restricted. Software components affected are: SAP Infrastructure 1.0, SAP UI 7.4, 7.5, 7.51, 7.52 and version 2.0 of SAP UI for SAP NetWeaver 7.00.

Affected Software

NameVendorStart VersionEnd Version
InfrastructureSap1.0 (including)1.0 (including)
UiSap2.0 (including)2.0 (including)
UiSap7.4 (including)7.4 (including)
UiSap7.5 (including)7.5 (including)
UiSap7.51 (including)7.51 (including)
UiSap7.52 (including)7.52 (including)

References