Vulnerability Description
SAP NetWeaver System Landscape Directory, LM-CORE 7.10, 7.20, 7.30, 7.31, 7.40, does not perform any authentication checks for functionalities that require user identity.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver System Landscape Directory | 7.10 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/103000Third Party AdvisoryVDB Entry
- https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2565622Permissions Required
- http://www.securityfocus.com/bid/103000Third Party AdvisoryVDB Entry
- https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2565622Permissions Required
FAQ
What is CVE-2018-2368?
CVE-2018-2368 is a vulnerability with a CVSS score of 9.8 (CRITICAL). SAP NetWeaver System Landscape Directory, LM-CORE 7.10, 7.20, 7.30, 7.31, 7.40, does not perform any authentication checks for functionalities that require user identity.
How severe is CVE-2018-2368?
CVE-2018-2368 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-2368?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Netweaver System Landscape Directory.