First published: Tue Nov 13 2018(Updated: )
It is possible for a malware application installed on an Android device to send local push notifications with an empty message to SAP Fiori Client and cause the application to crash. SAP Fiori Client version 1.11.5 in Google Play store addresses these issues and users must update to that version.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Fiori Client | <1.11.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-2488 is classified as a medium severity vulnerability that can cause the SAP Fiori Client application to crash.
To fix CVE-2018-2488, users should update the SAP Fiori Client to version 1.11.5 or later.
CVE-2018-2488 is caused by a malware application sending local push notifications with an empty message to the SAP Fiori Client.
CVE-2018-2488 affects all versions of SAP Fiori Client prior to 1.11.5.
No, CVE-2018-2488 specifically affects the SAP Fiori Client on Android devices.