CVE-2018-2424: Input Validation
SAP UI5 did not validate user input before adding it to the DOM structure. This may lead to malicious user-provided JavaScript code being added to the DOM that could steal user information. Software components affected are: SAP Hana Database 1.00, 2.00; SAP UI5 1.00; SAP UI5 (Java) 7.30, 7.31, 7.40, 7,50; SAP UI 7.40, 7.50, 7.51, 7.52, and version 2.0 of SAP UI for SAP NetWeaver 7.00
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this SAP vulnerability?
The vulnerability ID for this SAP vulnerability is CVE-2018-2424.
What is the severity of CVE-2018-2424?
The severity of CVE-2018-2424 is critical (7.5).
Which software components are affected by CVE-2018-2424?
The affected software components are SAP Hana Database 1.00, 2.00 and SAP UI5 1.00, SAP UI5 (Java) 7.30, 7.31, 7.40, 7.50, 7.51, 7.52.
How can CVE-2018-2424 be exploited?
CVE-2018-2424 can be exploited by adding malicious user-provided JavaScript code to the DOM structure in SAP UI5, which could lead to stealing user information.
Where can I find more information about CVE-2018-2424?
You can find more information about CVE-2018-2424 at the following references: [securityfocus.com](http://www.securityfocus.com/bid/104459), [launchpad.support.sap.com](https://launchpad.support.sap.com/#/notes/2538856), [wiki.scn.sap.com](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=495289255).