cbcvebase.
CVE-2018-2434
published 2018-07-10

CVE-2018-2434: A content spoofing vulnerability in the following components allows to render html pages containing arbitrary plain text content, which might fool an end user…

PriorityP420medium4.3CVSS 3.0
AVNACLPRNUIRSUCNILAN
EPSS
0.55%
42.3th percentile
A content spoofing vulnerability in the following components allows to render html pages containing arbitrary plain text content, which might fool an end user: UI add-on for SAP NetWeaver (UI_Infra, 1.0), SAP UI Implementation for Decoupled Innovations (UI_700, 2.0): SAP NetWeaver 7.00 Implementation, SAP User Interface Technology (SAP_UI 7.4, 7.5, 7.51, 7.52). There is little impact as it is not possible to embed active contents such as JavaScript or hyperlinks.

Affected

13 ranges
VendorProductVersion rangeFixed in
sapnetweaver
sapsap_netweaver
sapsap_netweaver
sapsap_ui_implementation_for_decoupled_innovations
sapsap_user_interface_technology
sapsap_user_interface_technology
sapsap_user_interface_technology
sapsap_user_interface_technology
sapui_infra
sapuser_interface_technology
sapuser_interface_technology
sapuser_interface_technology
sapuser_interface_technology

CVSS provenance

nvdv3.04.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.