CVE-2018-2380 KEV EXPLOIT
6.6
MEDIUM · CVSS 3.1 · EPSS 28.9% (pctl 98)
Patch first
On CISA KEV — known exploited in the wild, due 2022-05-03.
Description
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
Scoring
| CVSS | 6.6 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L |
| EPSS | 28.93% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | yes — remediate by 2022-05-03 |
| Public exploit | yes |
| Published | 2018-03-01 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | SAP Customer Relationship Management (CRM) Path Traversal Vulnerability |
|---|---|
| Added | 2021-11-03 |
| Due | 2022-05-03 |
| Vendor / product | SAP / Customer Relationship Management (CRM) |
| Ransomware use | known |
Affected (1)
| Vendor | Product |
|---|---|
| sap | customer relationship management |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | SAP NetWeaver AS JAVA CRM - Log injection Remote Command Execution | 2018-03-14 |
References
- http://www.securityfocus.com/bid/103001
- https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/
- https://github.com/erpscanteam/CVE-2018-2380
- https://launchpad.support.sap.com/#/notes/2547431
- https://www.exploit-db.com/exploits/44292/
- http://www.securityfocus.com/bid/103001
- https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/
- https://github.com/erpscanteam/CVE-2018-2380
- https://launchpad.support.sap.com/#/notes/2547431
- https://www.exploit-db.com/exploits/44292/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-2380
→ the Explorer · watch your stack · NVD