CVE-2018-2476: Medium severity sap netweaver vulnerability
Published Nov 13, 2018
·Updated
Due to insufficient URL Validation in forums in SAP NetWeaver versions 7.30, 7.31, 7.40, an attacker can redirect users to a malicious site.
Affected Software
3 affected components
SAP NetWeaver=7.30
SAP NetWeaver=7.31
SAP NetWeaver=7.40
Event History
Nov 13, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2018-2476.
2
What is the severity of CVE-2018-2476?
The severity of CVE-2018-2476 is medium.
3
Which SAP NetWeaver versions are affected by CVE-2018-2476?
SAP NetWeaver versions 7.30, 7.31, and 7.40 are affected by CVE-2018-2476.
4
What can an attacker do with CVE-2018-2476?
An attacker can redirect users to a malicious site using CVE-2018-2476.
5
Are there any references for CVE-2018-2476?
Yes, the following references are available: http://www.securityfocus.com/bid/105898, https://launchpad.support.sap.com/#/notes/2658755, https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=503809832