First published: Tue Dec 11 2018(Updated: )
Under certain conditions SAP Mobile Secure Android client (before version 6.60.19942.0 SP28 1711) allows an attacker to access information which would otherwise be restricted.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Mobile Secure Android | <=6.60.19942.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-2500 is rated as medium severity due to its potential to expose sensitive information.
To fix CVE-2018-2500, upgrade the SAP Mobile Secure Android client to version 6.60.19942.0 SP28 1711 or later.
CVE-2018-2500 affects SAP Mobile Secure Android clients before version 6.60.19942.0 SP28 1711.
CVE-2018-2500 allows unauthorized access to restricted information within the SAP Mobile Secure Android client.
There are no known effective workarounds for CVE-2018-2500, so upgrading to a patched version is recommended.