First published: Tue Apr 10 2018(Updated: )
SAP Solution Manager, 7.10, 7.20, Incident Management Work Center allows an attacker to upload a malicious script as an attachment and this could lead to possible Cross-Site Scripting.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Solution Manager | =7.10 | |
SAP Solution Manager | =7.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-2405 is a vulnerability in SAP Solution Manager 7.10 and 7.20 that allows an attacker to upload a malicious script as an attachment, potentially leading to Cross-Site Scripting (XSS).
CVE-2018-2405 affects SAP Solution Manager 7.10 and 7.20, specifically the Incident Management Work Center, where an attacker can upload a malicious script as an attachment.
CVE-2018-2405 has a severity rating of 5.4, which is considered medium.
An attacker can exploit CVE-2018-2405 by uploading a malicious script as an attachment in the Incident Management Work Center of SAP Solution Manager 7.10 and 7.20, potentially leading to Cross-Site Scripting (XSS).
Yes, SAP has released a security patch to address CVE-2018-2405. It is recommended to apply the patch to protect against this vulnerability.