CVE-2018-2478: High severity sap basis component 700 vulnerability
An attacker can use specially crafted inputs to execute commands on the host of a TREX / BWA installation, SAP Basis, versions: 7.0 to 7.02, 7.10 to 7.11, 7.30, 7.31, 7.40 and 7.50 to 7.53. Not all commands are possible, only those that can be executed by the <sid>adm user. The commands executed depend upon the privileges of the <sid>adm user.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-2478?
CVE-2018-2478 is a vulnerability that allows an attacker to execute commands on the host of a SAP Basis installation.
What is the severity of CVE-2018-2478?
CVE-2018-2478 has a severity rating of 7.2, which is considered high.
Which versions of SAP Basis are affected by CVE-2018-2478?
CVE-2018-2478 affects SAP Basis versions 7.0 to 7.02, 7.10 to 7.11, 7.30, 7.31, 7.40, and 7.50 to 7.53.
What can an attacker do with CVE-2018-2478?
An attacker can execute commands on the host of a SAP Basis installation, but only those that can be executed by the <sid>adm user.
How can I fix CVE-2018-2478?
To fix CVE-2018-2478, apply the necessary patches provided by SAP.