CVE-2018-2459: High severity sap mobile platform sdk vulnerability
Published Sep 11, 2018
·Updated
Users of an SAP Mobile Platform (version 3.0) Offline OData application, which uses Offline OData-supplied delta tokens (which is on by default), occasionally receive some data values of a different user.
Affected Software
1 affected component
SAP Mobile Platform=3.0
Event History
Sep 11, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this SAP Mobile Platform vulnerability?
The vulnerability ID for this SAP Mobile Platform vulnerability is CVE-2018-2459.
2
Which version of SAP Mobile Platform is affected by this vulnerability?
SAP Mobile Platform version 3.0 is affected by this vulnerability.
3
What is the severity of CVE-2018-2459?
CVE-2018-2459 has a severity score of 7.5 (High).
4
What is the impact of this vulnerability?
The impact of this vulnerability is that users of SAP Mobile Platform offline OData applications may receive data values of a different user.
5
Are there any known solutions or mitigations for this vulnerability?
Yes, SAP has released a note with a patch and additional recommendations to mitigate this vulnerability. Please refer to the SAP Launchpad for more details.