CVE-2018-2428: Medium severity sap infrastructure vulnerability
Under certain conditions SAP UI5 Handler allows an attacker to access information which would otherwise be restricted. Software components affected are: SAP Infrastructure 1.0, SAP UI 7.4, 7.5, 7.51, 7.52 and version 2.0 of SAP UI for SAP NetWeaver 7.00.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-2428?
CVE-2018-2428 is a vulnerability that allows an attacker to access restricted information in certain conditions in SAP UI5 Handler.
Which software components are affected by CVE-2018-2428?
The affected software components are SAP Infrastructure 1.0, SAP UI 7.4, 7.5, 7.51, 7.52, and version 2.0 of SAP UI for SAP NetWeaver 7.00.
What is the severity of CVE-2018-2428?
The severity of CVE-2018-2428 is medium, with a severity rating of 5.3.
How can I fix CVE-2018-2428?
To fix CVE-2018-2428, it is recommended to apply the necessary patches provided by SAP.
Where can I find more information about CVE-2018-2428?
You can find more information about CVE-2018-2428 at the following references: [http://www.securityfocus.com/bid/104446](http://www.securityfocus.com/bid/104446), [https://launchpad.support.sap.com/#/notes/2621121](https://launchpad.support.sap.com/#/notes/2621121), [https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=495289255](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=495289255)