CVE-2018-2489: High severity sap fiori client vulnerability
Published Nov 13, 2018
·Updated
Locally, without any permission, an arbitrary android application could delete the SSO configuration of SAP Fiori Client. SAP Fiori Client version 1.11.5 in Google Play store addresses these issues and users must update to that version.
Affected Software
1 affected component
SAP Fiori Client<1.11.5
Event History
Nov 13, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-2489?
CVE-2018-2489 has a high severity as it allows unauthorized deletion of the Single Sign-On configuration.
2
How do I fix CVE-2018-2489?
To fix CVE-2018-2489, update your SAP Fiori Client to version 1.11.5 or later.
3
Who is affected by CVE-2018-2489?
Users of SAP Fiori Client versions prior to 1.11.5 are affected by CVE-2018-2489.
4
What are the impacts of CVE-2018-2489?
CVE-2018-2489 allows arbitrary applications to delete the SSO configuration, potentially leading to unauthorized access.
5
Is there a workaround for CVE-2018-2489?
There is no known workaround for CVE-2018-2489 other than updating to the fixed version.