CVE-2018-2415: Medium severity sap netweaver java web container and http service engine vulnerability
SAP NetWeaver Application Server Java Web Container and HTTP Service (Engine API, from 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; J2EE Engine Server Core 7.11, 7.30, 7.31, 7.40, 7.50) do not sufficiently encode user controlled inputs, resulting in a content spoofing vulnerability when error pages are displayed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-2415?
CVE-2018-2415 has been rated as a medium severity vulnerability.
How do I fix CVE-2018-2415?
To fix CVE-2018-2415, upgrade to the latest version of SAP NetWeaver Application Server Java Web Container or J2EE Engine Server Core that is not affected by this vulnerability.
What types of inputs are vulnerable in CVE-2018-2415?
CVE-2018-2415 involves the insufficient encoding of user-controlled inputs resulting in content spoofing.
Which SAP products are affected by CVE-2018-2415?
CVE-2018-2415 affects various versions of SAP NetWeaver Application Server Java and J2EE Engine Server Core from 7.10 to 7.50.
What are the potential impacts of CVE-2018-2415?
The potential impacts of CVE-2018-2415 include content spoofing, which could mislead users and undermine trust.