Vulnerability Description
Knowledge Management (XMLForms) in SAP NetWeaver, versions 7.30, 7.31, 7.40 and 7.50 does not sufficiently validate an XML document accepted from an untrusted source.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Netweaver | 7.30 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/105901Third Party AdvisoryVDB Entry
- https://launchpad.support.sap.com/#/notes/2661740Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=503809832Vendor Advisory
- http://www.securityfocus.com/bid/105901Third Party AdvisoryVDB Entry
- https://launchpad.support.sap.com/#/notes/2661740Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=503809832Vendor Advisory
FAQ
What is CVE-2018-2477?
CVE-2018-2477 is a vulnerability with a CVSS score of 8.8 (HIGH). Knowledge Management (XMLForms) in SAP NetWeaver, versions 7.30, 7.31, 7.40 and 7.50 does not sufficiently validate an XML document accepted from an untrusted source.
How severe is CVE-2018-2477?
CVE-2018-2477 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-2477?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Netweaver.