First published: Tue Jun 12 2018(Updated: )
Under certain conditions SAP UI5 Handler allows an attacker to access information which would otherwise be restricted. Software components affected are: SAP Infrastructure 1.0, SAP UI 7.4, 7.5, 7.51, 7.52 and version 2.0 of SAP UI for SAP NetWeaver 7.00.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Infrastructure | =1.0 | |
Sap Ui | =2.0 | |
SAP UI | =7.4 | |
SAP UI | =7.5 | |
SAP UI | =7.51 | |
SAP UI | =7.52 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-2428 is a vulnerability that allows an attacker to access restricted information in certain conditions in SAP UI5 Handler.
The affected software components are SAP Infrastructure 1.0, SAP UI 7.4, 7.5, 7.51, 7.52, and version 2.0 of SAP UI for SAP NetWeaver 7.00.
The severity of CVE-2018-2428 is medium, with a severity rating of 5.3.
To fix CVE-2018-2428, it is recommended to apply the necessary patches provided by SAP.
You can find more information about CVE-2018-2428 at the following references: [http://www.securityfocus.com/bid/104446](http://www.securityfocus.com/bid/104446), [https://launchpad.support.sap.com/#/notes/2621121](https://launchpad.support.sap.com/#/notes/2621121), [https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=495289255](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=495289255)