CVE-2018-2505: Code Injection
Published Dec 11, 2018
·Updated
SAP Commerce does not sufficiently validate user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability in storefronts that are based on the product. Fixed in versions (SAP Hybris Commerce, versions 6.2, 6.3, 6.4, 6.5, 6.6, 6.7).
Affected Software
6 affected components
SAP Hybris=6.2
SAP Hybris=6.3
SAP Hybris=6.4
SAP Hybris=6.5
SAP Hybris=6.6
SAP Hybris=6.7
Event History
Dec 11, 2018
CVE Published
10:29 PM
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-2505?
CVE-2018-2505 has a medium severity rating due to its potential to allow cross-site scripting attacks.
2
How do I fix CVE-2018-2505?
To fix CVE-2018-2505, upgrade SAP Hybris Commerce to version 6.8 or later.
3
What types of applications are affected by CVE-2018-2505?
CVE-2018-2505 affects storefront applications based on SAP Commerce that do not sufficiently validate user inputs.
4
Can CVE-2018-2505 be exploited by unauthenticated users?
Yes, CVE-2018-2505 can be exploited by unauthenticated users due to the nature of cross-site scripting.
5
What are the impacted versions of SAP Hybris due to CVE-2018-2505?
The impacted versions of SAP Hybris due to CVE-2018-2505 are 6.2, 6.3, 6.4, 6.5, 6.6, and 6.7.