First published: Tue Sep 11 2018(Updated: )
Users of an SAP Mobile Platform (version 3.0) Offline OData application, which uses Offline OData-supplied delta tokens (which is on by default), occasionally receive some data values of a different user.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Mobile Platform | =3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this SAP Mobile Platform vulnerability is CVE-2018-2459.
SAP Mobile Platform version 3.0 is affected by this vulnerability.
CVE-2018-2459 has a severity score of 7.5 (High).
The impact of this vulnerability is that users of SAP Mobile Platform offline OData applications may receive data values of a different user.
Yes, SAP has released a note with a patch and additional recommendations to mitigate this vulnerability. Please refer to the SAP Launchpad for more details.