Vulnerability Description
Under certain conditions SAP SRM-MDM (CATALOG versions 3.0, 7.01, 7.02) utilities functionality allows an attacker to access information of user existence which would otherwise be restricted.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Supplier Relationship Management Mdm Catalog | 3.0 |
References
- http://www.securityfocus.com/bid/105077Third Party AdvisoryVDB Entry
- https://launchpad.support.sap.com/#/notes/2653846Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499352742Vendor Advisory
- http://www.securityfocus.com/bid/105077Third Party AdvisoryVDB Entry
- https://launchpad.support.sap.com/#/notes/2653846Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499352742Vendor Advisory
FAQ
What is CVE-2018-2448?
CVE-2018-2448 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Under certain conditions SAP SRM-MDM (CATALOG versions 3.0, 7.01, 7.02) utilities functionality allows an attacker to access information of user existence which would otherwise be restricted.
How severe is CVE-2018-2448?
CVE-2018-2448 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-2448?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Supplier Relationship Management Mdm Catalog.