CVE-2018-2450: SQL Injection
Published Aug 14, 2018
·Updated
SAP MaxDB (liveCache), versions 7.8 and 7.9, allows an attacker who gets DBM operator privileges to execute crafted database queries and therefore read, modify or delete sensitive data from database.
Affected Software
2 affected components
SAP MaxDB=7.8
SAP MaxDB=7.9
Event History
Aug 14, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-2450?
CVE-2018-2450 is considered a critical vulnerability due to its potential impact on sensitive data manipulation.
2
How do I fix CVE-2018-2450?
To fix CVE-2018-2450, it is recommended to upgrade SAP MaxDB to versions 7.8 or 7.9 to apply the necessary security patches.
3
Who is affected by CVE-2018-2450?
CVE-2018-2450 affects users of SAP MaxDB versions 7.8 and 7.9 who have DBM operator privileges.
4
What type of attacks are possible with CVE-2018-2450?
With CVE-2018-2450, an attacker can execute crafted database queries to read, modify, or delete sensitive data.
5
What are the impacted products of CVE-2018-2450?
The impacted products of CVE-2018-2450 are SAP MaxDB versions 7.8 and 7.9.