CVE-2018-2388: XSS
Published Feb 14, 2018
·Updated
Stored cross-site scripting vulnerability in SAP internet Graphics Server, 7.20, 7.20EXT, 7.45, 7.49, 7.53.
Affected Software
5 affected components
SAP Internet Graphics Server=7.20
SAP Internet Graphics Server=7.20ext
SAP Internet Graphics Server=7.45
SAP Internet Graphics Server=7.49
SAP Internet Graphics Server=7.53
Event History
Feb 14, 2018
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-2388?
CVE-2018-2388 is a stored cross-site scripting vulnerability in SAP internet Graphics Server versions 7.20, 7.20EXT, 7.45, 7.49, and 7.53.
2
What is the severity of CVE-2018-2388?
CVE-2018-2388 has a severity rating of 6.1 or medium.
3
How does CVE-2018-2388 affect SAP internet Graphics Server?
CVE-2018-2388 allows attackers to inject malicious scripts into the server, potentially leading to cross-site scripting attacks on users.
4
How can I mitigate the risks associated with CVE-2018-2388?
To mitigate the risks of CVE-2018-2388, it is recommended to apply the patches provided by SAP.
5
Where can I find more information about CVE-2018-2388?
More information about CVE-2018-2388 can be found in the SAP Security Patch Day February 2018 blog post and the related SAP note.