CVE-2018-2470: XSS
In SAP NetWeaver Application Server for ABAP, from 7.0 to 7.02, 7.30, 7.31, 7.40 and from 7.50 to 7.53, applications do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-2470?
The severity of CVE-2018-2470 is medium, with a severity value of 6.1.
What is the vulnerability of CVE-2018-2470?
CVE-2018-2470 is a Cross-Site Scripting (XSS) vulnerability.
Which versions of SAP NetWeaver Application Server for ABAP are affected by CVE-2018-2470?
CVE-2018-2470 affects SAP NetWeaver Application Server for ABAP versions 7.0 to 7.02, 7.30, 7.31, 7.40, and 7.50 to 7.53.
How can I fix CVE-2018-2470?
To fix CVE-2018-2470, update your SAP NetWeaver Application Server for ABAP to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2018-2470?
You can find more information about CVE-2018-2470 at the following references: [1] http://www.securityfocus.com/bid/105551 [2] https://launchpad.support.sap.com/#/notes/2684760 [3] https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=500633095