Vulnerability Description
SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid repository user. This is an unauthenticated functionality that you can use on windows machines to do SMB relaying.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Supplier Relationship Management Mdm Catalog | 3.73 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/105079Third Party AdvisoryVDB Entry
- https://launchpad.support.sap.com/#/notes/2655250Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499352742Vendor Advisory
- http://www.securityfocus.com/bid/105079Third Party AdvisoryVDB Entry
- https://launchpad.support.sap.com/#/notes/2655250Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499352742Vendor Advisory
FAQ
What is CVE-2018-2449?
CVE-2018-2449 is a vulnerability with a CVSS score of 8.6 (HIGH). SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid repository user. This is an unauthenticated functionality t...
How severe is CVE-2018-2449?
CVE-2018-2449 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-2449?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Supplier Relationship Management Mdm Catalog.