CVE Vulnerabilities

CVE-2018-2448

Published: Aug 14, 2018 | Modified: Aug 24, 2020
CVSS 3.x
5.3
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Under certain conditions SAP SRM-MDM (CATALOG versions 3.0, 7.01, 7.02) utilities functionality allows an attacker to access information of user existence which would otherwise be restricted.

Affected Software

Name Vendor Start Version End Version
Supplier_relationship_management_mdm_catalog Sap 3.0 (including) 3.0 (including)
Supplier_relationship_management_mdm_catalog Sap 7.01 (including) 7.01 (including)
Supplier_relationship_management_mdm_catalog Sap 7.02 (including) 7.02 (including)

References