Vulnerability Description
Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud Connector). Under certain conditions, data of some other user may be shown or modified when using an application built on top of SAP Cloud Platform.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Cloud Platform | 2.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/103702Third Party AdvisoryVDB Entry
- https://blogs.sap.com/2018/04/10/sap-security-patch-day-april-2018/Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2614141Permissions Required
- http://www.securityfocus.com/bid/103702Third Party AdvisoryVDB Entry
- https://blogs.sap.com/2018/04/10/sap-security-patch-day-april-2018/Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2614141Permissions Required
FAQ
What is CVE-2018-2409?
CVE-2018-2409 is a vulnerability with a CVSS score of 6.3 (MEDIUM). Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud Connector). Under certain conditions, data of some other user may be shown or modified when using an appli...
How severe is CVE-2018-2409?
CVE-2018-2409 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-2409?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Cloud Platform.