First published: Tue Dec 11 2018(Updated: )
SAP Marketing (UICUAN (1.20, 1.30, 1.40), SAPSCORE (1.13, 1.14)) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP SAPscore | =1.13 | |
SAP SAPscore | =1.14 | |
SAP Marketing Cloud | =1.20 | |
SAP Marketing Cloud | =1.30 | |
SAP Marketing Cloud | =1.40 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-2486 has a medium severity rating due to its Cross-Site Scripting (XSS) risk.
To fix CVE-2018-2486, ensure that user-controlled inputs are properly encoded before being rendered in the application.
CVE-2018-2486 affects SAP Marketing UICUAN versions 1.20, 1.30, 1.40 and SAPSCORE versions 1.13 and 1.14.
CVE-2018-2486 is a Cross-Site Scripting (XSS) vulnerability caused by insufficient encoding of user inputs.
The potential impacts of CVE-2018-2486 include theft of session tokens, redirection to malicious sites, and unauthorized access to user data.