First published: Tue Nov 13 2018(Updated: )
Knowledge Management (XMLForms) in SAP NetWeaver, versions 7.30, 7.31, 7.40 and 7.50 does not sufficiently validate an XML document accepted from an untrusted source.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP NetWeaver | =7.30 | |
SAP NetWeaver | =7.31 | |
SAP NetWeaver | =7.40 | |
SAP NetWeaver | =7.50 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2018-2477.
The severity of CVE-2018-2477 is high with a CVSS score of 8.8.
The affected software versions are SAP NetWeaver 7.30, 7.31, 7.40, and 7.50.
The vulnerability in SAP Knowledge Management (XMLForms) is the insufficient validation of XML documents accepted from untrusted sources.
You can find more information about CVE-2018-2477 at the following references: [1](http://www.securityfocus.com/bid/105901), [2](https://launchpad.support.sap.com/#/notes/2661740), [3](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=503809832).