CVE-2018-2363: Code Injection
SAP NetWeaver, SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, contains code that allows you to execute arbitrary program code of the user's choice. A malicious user can therefore control the behaviour of the system or can potentially escalate privileges by executing malicious code without legitimate credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-2363?
The severity of CVE-2018-2363 is high with a severity value of 8.8.
Which SAP software versions are affected by CVE-2018-2363?
SAP NetWeaver, SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, and Sap Business Application Software Integrated Solution versions 7.00 to 7.02, 7.10 to 7.11, 7.30, 7.31, 7.40, and 7.50 to 7.52 are affected by CVE-2018-2363.
What is the risk of CVE-2018-2363?
CVE-2018-2363 allows a malicious user to execute arbitrary program code of the user's choice, potentially leading to control over the system behavior or privilege escalation.
How can I fix CVE-2018-2363?
Apply the security patch provided by SAP, which can be found at the SAP Security Patch Day January 2018 (https://blogs.sap.com/2018/01/09/sap-security-patch-day-january-2018/), or refer to SAP Note 1906212 (https://launchpad.support.sap.com/#/notes/1906212) for more information on mitigating the vulnerability.
Where can I find more information about CVE-2018-2363?
You can find more information about CVE-2018-2363 at the following references: SecurityFocus (http://www.securityfocus.com/bid/102449), SAP Security Patch Day January 2018 (https://blogs.sap.com/2018/01/09/sap-security-patch-day-january-2018/), and SAP Note 1906212 (https://launchpad.support.sap.com/#/notes/1906212).