CVE-2018-2460: Medium severity sap business one vulnerability
Published Sep 11, 2018
·Updated
SAP Business One Android application, version 1.2, does not verify the certificate properly for HTTPS connection. This allows attacker to do MITM attack.
Affected Software
1 affected component
SAP Business One Android=1.2
Event History
Sep 11, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-2460?
CVE-2018-2460 is considered a high severity vulnerability due to its potential for enabling man-in-the-middle attacks.
2
How do I fix CVE-2018-2460?
To mitigate CVE-2018-2460, update the SAP Business One Android application to a version that properly verifies HTTPS certificates.
3
What type of attack does CVE-2018-2460 allow?
CVE-2018-2460 allows attackers to perform man-in-the-middle (MITM) attacks due to improper certificate verification.
4
Which version of SAP Business One is affected by CVE-2018-2460?
CVE-2018-2460 specifically affects SAP Business One Android application version 1.2.
5
Is CVE-2018-2460 a client-side or server-side vulnerability?
CVE-2018-2460 is a client-side vulnerability affecting the SAP Business One Android application.