CVE-2018-2405: XSS
SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a malicious script as an attachment and this could lead to possible Cross-Site Scripting.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-2405?
CVE-2018-2405 is a vulnerability in SAP Solution Manager 7.10 and 7.20 that allows an attacker to upload a malicious script as an attachment, potentially leading to Cross-Site Scripting (XSS).
How does CVE-2018-2405 affect SAP Solution Manager?
CVE-2018-2405 affects SAP Solution Manager 7.10 and 7.20, specifically the Incident Management Work Center, where an attacker can upload a malicious script as an attachment.
What is the severity of CVE-2018-2405?
CVE-2018-2405 has a severity rating of 5.4, which is considered medium.
How can an attacker exploit CVE-2018-2405?
An attacker can exploit CVE-2018-2405 by uploading a malicious script as an attachment in the Incident Management Work Center of SAP Solution Manager 7.10 and 7.20, potentially leading to Cross-Site Scripting (XSS).
Is there a security patch available for CVE-2018-2405?
Yes, SAP has released a security patch to address CVE-2018-2405. It is recommended to apply the patch to protect against this vulnerability.