CVE-2018-2474: CSRF
SAP Fiori 1.0 for SAP ERP HCM (Approve Leave Request, version 2) application allows an attacker to trick an authenticated user to send unintended request to the web server. This vulnerability is due to insufficient CSRF protection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-2474?
CVE-2018-2474 has been rated as a medium severity vulnerability due to its potential for CSRF attacks.
How do I fix CVE-2018-2474?
To mitigate CVE-2018-2474, implement proper CSRF protection mechanisms in your SAP Fiori application.
Who is affected by CVE-2018-2474?
CVE-2018-2474 affects users of SAP Fiori 1.0 for SAP ERP HCM specifically in the Approve Leave Request application.
What are the implications of CVE-2018-2474?
If exploited, CVE-2018-2474 can allow attackers to perform actions on behalf of the authenticated user without their consent.
When was CVE-2018-2474 disclosed?
CVE-2018-2474 was disclosed in 2018, highlighting the need for improved security in SAP applications.