CVE-2018-2448: Medium severity sap supplier relationship management vulnerability
Published Aug 14, 2018
·Updated
Under certain conditions SAP SRM-MDM (CATALOG versions 3.0, 7.01, 7.02) utilities functionality allows an attacker to access information of user existence which would otherwise be restricted.
Affected Software
3 affected components
SAP Supplier Relationship Management Mdm Catalog=3.0
SAP Supplier Relationship Management Mdm Catalog=7.01
SAP Supplier Relationship Management Mdm Catalog=7.02
Event History
Aug 14, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-2448?
CVE-2018-2448 has been classified as a medium-severity vulnerability.
2
How do I fix CVE-2018-2448?
To fix CVE-2018-2448, ensure you apply the latest security patches provided by SAP for the affected versions.
3
Who is affected by CVE-2018-2448?
CVE-2018-2448 affects users of SAP Supplier Relationship Management MDM Catalog versions 3.0, 7.01, and 7.02.
4
What type of vulnerability is CVE-2018-2448?
CVE-2018-2448 is a vulnerability that allows unauthorized access to user existence information.
5
What is the potential impact of CVE-2018-2448?
The potential impact of CVE-2018-2448 is unauthorized information disclosure regarding user existence in the affected SAP applications.