First published: Wed Feb 14 2018(Updated: )
SAP ERP Financials Information System (SAP_APPL 6.00, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16; SAP_FIN 6.17, 6.18, 7.00, 7.20, 7.30 S4CORE 1.00, 1.01, 1.02) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP ERP Financials Information System | =2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-2381 is classified as a critical vulnerability due to the potential for privilege escalation.
CVE-2018-2381 affects SAP ERP Financials Information System by allowing authenticated users to bypass authorization checks.
CVE-2018-2381 impacts SAP ERP Financials Information System versions 6.00 through 7.30, as well as S4CORE 1.00 through 1.02.
To fix CVE-2018-2381, apply the latest security patches provided by SAP for affected versions.
If left unaddressed, CVE-2018-2381 can lead to unauthorized access and potential control over sensitive financial data.