CVE-2018-2365: XSS
Published Mar 1, 2018
·Updated
SAP NetWeaver Portal, WebDynpro Java, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Affected Software
4 affected components
SAP NetWeaver Portal=7.30
SAP NetWeaver Portal=7.31
SAP NetWeaver Portal=7.40
SAP NetWeaver Portal=7.50
Event History
Mar 1, 2018
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-2365?
CVE-2018-2365 is classified as a medium severity vulnerability due to its potential for exploitation through Cross-Site Scripting.
2
How do I fix CVE-2018-2365?
Fixing CVE-2018-2365 involves applying the latest security patches provided by SAP for the affected versions of NetWeaver Portal.
3
Which versions of SAP are affected by CVE-2018-2365?
CVE-2018-2365 affects SAP NetWeaver Portal versions 7.30, 7.31, 7.40, and 7.50.
4
What type of vulnerability is CVE-2018-2365?
CVE-2018-2365 is a Cross-Site Scripting (XSS) vulnerability caused by insufficient encoding of user-controlled inputs.
5
Can CVE-2018-2365 be exploited remotely?
Yes, CVE-2018-2365 can be exploited remotely, allowing attackers to execute scripts in the context of a user's browser.