CVE-2018-2488: High severity sap fiori client vulnerability
It is possible for a malware application installed on an Android device to send local push notifications with an empty message to SAP Fiori Client and cause the application to crash. SAP Fiori Client version 1.11.5 in Google Play store addresses these issues and users must update to that version.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-2488?
CVE-2018-2488 is classified as a medium severity vulnerability that can cause the SAP Fiori Client application to crash.
How do I fix CVE-2018-2488?
To fix CVE-2018-2488, users should update the SAP Fiori Client to version 1.11.5 or later.
What causes the vulnerability CVE-2018-2488?
CVE-2018-2488 is caused by a malware application sending local push notifications with an empty message to the SAP Fiori Client.
Which versions of SAP Fiori Client are affected by CVE-2018-2488?
CVE-2018-2488 affects all versions of SAP Fiori Client prior to 1.11.5.
Is CVE-2018-2488 applicable to devices outside of Android?
No, CVE-2018-2488 specifically affects the SAP Fiori Client on Android devices.