CVE-2018-2486: XSS
Published Dec 11, 2018
·Updated
SAP Marketing (UICUAN (1.20, 1.30, 1.40), SAPSCORE (1.13, 1.14)) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Affected Software
5 affected components
SAP Marketing Sapscore=1.13
SAP Marketing Sapscore=1.14
SAP Marketing Uicuan=1.20
SAP Marketing Uicuan=1.30
SAP Marketing Uicuan=1.40
Event History
Dec 11, 2018
CVE Published
10:29 PM
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-2486?
CVE-2018-2486 has a medium severity rating due to its Cross-Site Scripting (XSS) risk.
2
How do I fix CVE-2018-2486?
To fix CVE-2018-2486, ensure that user-controlled inputs are properly encoded before being rendered in the application.
3
Which versions of SAP Marketing are affected by CVE-2018-2486?
CVE-2018-2486 affects SAP Marketing UICUAN versions 1.20, 1.30, 1.40 and SAPSCORE versions 1.13 and 1.14.
4
What type of vulnerability is CVE-2018-2486?
CVE-2018-2486 is a Cross-Site Scripting (XSS) vulnerability caused by insufficient encoding of user inputs.
5
What are the potential impacts of CVE-2018-2486?
The potential impacts of CVE-2018-2486 include theft of session tokens, redirection to malicious sites, and unauthorized access to user data.