First published: Tue Jan 09 2018(Updated: )
SAP NetWeaver, SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, contains code that allows you to execute arbitrary program code of the user's choice. A malicious user can therefore control the behaviour of the system or can potentially escalate privileges by executing malicious code without legitimate credentials.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver | ||
Sap Business Application Software Integrated Solution | >=7.00<=7.02 | |
Sap Business Application Software Integrated Solution | >=7.10<=7.11 | |
Sap Business Application Software Integrated Solution | >=7.50<=7.52 | |
Sap Business Application Software Integrated Solution | =7.30 | |
Sap Business Application Software Integrated Solution | =7.31 | |
Sap Business Application Software Integrated Solution | =7.40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-2363 is high with a severity value of 8.8.
SAP NetWeaver, SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, and Sap Business Application Software Integrated Solution versions 7.00 to 7.02, 7.10 to 7.11, 7.30, 7.31, 7.40, and 7.50 to 7.52 are affected by CVE-2018-2363.
CVE-2018-2363 allows a malicious user to execute arbitrary program code of the user's choice, potentially leading to control over the system behavior or privilege escalation.
Apply the security patch provided by SAP, which can be found at the SAP Security Patch Day January 2018 (https://blogs.sap.com/2018/01/09/sap-security-patch-day-january-2018/), or refer to SAP Note 1906212 (https://launchpad.support.sap.com/#/notes/1906212) for more information on mitigating the vulnerability.
You can find more information about CVE-2018-2363 at the following references: SecurityFocus (http://www.securityfocus.com/bid/102449), SAP Security Patch Day January 2018 (https://blogs.sap.com/2018/01/09/sap-security-patch-day-january-2018/), and SAP Note 1906212 (https://launchpad.support.sap.com/#/notes/1906212).