CVE-2018-2503: High severity sap netweaver as for java vulnerability
By default, the SAP NetWeaver AS Java keystore service does not sufficiently restrict the access to resources that should be protected. This has been fixed in SAP NetWeaver AS Java (ServerCore versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-2503?
CVE-2018-2503 is a vulnerability in the SAP NetWeaver AS Java keystore service that allows unauthorized access to protected resources.
How severe is CVE-2018-2503?
CVE-2018-2503 has a severity rating of 7.4/10, which is considered high.
Which versions of SAP NetWeaver Application Server Java are affected by CVE-2018-2503?
SAP NetWeaver Application Server Java versions 7.11, 7.20, 7.30, 7.31, 7.40, and 7.50 are affected by CVE-2018-2503.
How can I fix CVE-2018-2503?
To fix CVE-2018-2503, you should apply the relevant security patch provided by SAP.
Where can I find more information about CVE-2018-2503?
You can find more information about CVE-2018-2503 on the following references: [securityfocus.com](http://www.securityfocus.com/bid/106156), [SAP Notes](https://launchpad.support.sap.com/#/notes/2658279), and [SAP Wiki](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=508559699).