cbcvebase.
CVE-2018-2428
published 2018-06-12

CVE-2018-2428: Under certain conditions SAP UI5 Handler allows an attacker to access information which would otherwise be restricted. Software components affected are: SAP…

PriorityP428medium5.3CVSS 3.0
AVNACLPRNUINSUCLINAN
EPSS
1.76%
75.5th percentile
Under certain conditions SAP UI5 Handler allows an attacker to access information which would otherwise be restricted. Software components affected are: SAP Infrastructure 1.0, SAP UI 7.4, 7.5, 7.51, 7.52 and version 2.0 of SAP UI for SAP NetWeaver 7.00.

Affected

12 ranges
VendorProductVersion rangeFixed in
sapinfrastructure
sapui
sapui
sapui
sapui
sapui
sap_sesap_infrastructure
sap_sesap_ui
sap_sesap_ui
sap_sesap_ui
sap_sesap_ui
sap_sesap_ui_for_sap_netweaver_7.00

CVSS provenance

nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.