CVE-2018-2434: Medium severity SAP NetWeaver vulnerability
A content spoofing vulnerability in the following components allows to render html pages containing arbitrary plain text content, which might fool an end user: UI add-on for SAP NetWeaver (UIInfra, 1.0), SAP UI Implementation for Decoupled Innovations (UI700, 2.0): SAP NetWeaver 7.00 Implementation, SAP User Interface Technology (SAPUI 7.4, 7.5, 7.51, 7.52). There is little impact as it is not possible to embed active contents such as JavaScript or hyperlinks.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-2434?
CVE-2018-2434 is a content spoofing vulnerability in certain SAP components that allows rendering of HTML pages containing arbitrary plain text content.
Which components are affected by CVE-2018-2434?
UI add-on for SAP NetWeaver (UI_Infra 1.0), SAP UI Implementation for Decoupled Innovations (UI_700 2.0), SAP NetWeaver 7.00 Implementation are affected by CVE-2018-2434.
What is the severity level of CVE-2018-2434?
CVE-2018-2434 has a severity level of medium with a CVSS score of 4.3.
How can I fix CVE-2018-2434?
To fix CVE-2018-2434, update the affected SAP components to the latest patched versions.
Where can I find more information about CVE-2018-2434?
You can find more information about CVE-2018-2434 on the following sources: [SecurityFocus](http://www.securityfocus.com/bid/105088), [SAP Note](https://launchpad.support.sap.com/#/notes/2633180), [SAP SCN Wiki](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=497256000).