CVE-2018-2367

CWE-22Path Traversal3 documents3 sources
Severity
8.8HIGH
EPSS
1.8%
top 17.18%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 1
Latest updateMay 14

Description

ABAP File Interface in, SAP BASIS, from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-r33j-jx63-m9vf: ABAP File Interface in, SAP BASIS, from 72022-05-14
CVEList
CVE-2018-2367: ABAP File Interface in, SAP BASIS, from 72018-03-01
CVE-2018-2367 (HIGH CVSS 8.8) | ABAP File Interface in | cvebase.io