CVE-2018-2435
published 2018-07-10CVE-2018-2435: SAP NetWeaver Enterprise Portal from 7.0 to 7.02, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting in…
PriorityP424medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
1.02%
59.5th percentile
SAP NetWeaver Enterprise Portal from 7.0 to 7.02, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | netweaver_enterprise_portal | — | — |
| sap | netweaver_enterprise_portal | — | — |
| sap | netweaver_enterprise_portal | — | — |
| sap | netweaver_enterprise_portal | — | — |
| sap | netweaver_enterprise_portal | — | — |
| sap | netweaver_enterprise_portal | — | — |
| sap | netweaver_enterprise_portal | 7.0 – 7.02 | — |
| sap | sap_netweaver_enterprise_portal | — | — |
| sap | sap_netweaver_enterprise_portal | — | — |
| sap | sap_netweaver_enterprise_portal | — | — |
| sap | sap_netweaver_enterprise_portal | — | — |
| sap | sap_netweaver_enterprise_portal | — | — |
| sap | sap_netweaver_enterprise_portal | — | — |
| sap | sap_netweaver_enterprise_portal | — | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-12824 CVE-2018-12826 CVE-2018-12827 flash-plugin: Information Disclosure vulnerabilities (APSB18-25)
bugzilla·2018-08-14·CVSS 5.9
CVE-2018-12824 [MEDIUM] CVE-2018-12824 CVE-2018-12826 CVE-2018-12827 flash-plugin: Information Disclosure vulnerabilities (APSB18-25)
CVE-2018-12824 CVE-2018-12826 CVE-2018-12827 flash-plugin: Information Disclosure vulnerabilities (APSB18-25)
Adobe Security Bulletin APSB18-25 for Adobe Flash Player describes a flaw that can possibly lead to information disclosure when Flash Player is used to play a specially crafted SWF file:
Out-of-bounds read -- CVE-2018-12824, CVE-2018-12826, CVE-2018-12827
External References:
https://helpx.adobe.com/security/products/flash-player/apsb18-25.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:2435 https://access.redhat.com/errata/RHSA-2018:2435
Bugzilla
CVE-2018-12825 flash-plugin: Security Mitigation Bypass vulnerability (APSB18-25)
bugzilla·2018-08-14·CVSS 9.8
CVE-2018-12825 [CRITICAL] CVE-2018-12825 flash-plugin: Security Mitigation Bypass vulnerability (APSB18-25)
CVE-2018-12825 flash-plugin: Security Mitigation Bypass vulnerability (APSB18-25)
Adobe Security Bulletin APSB18-25 for Adobe Flash Player describes a flaw that can possibly lead to security mitigation bypass when Flash Player is used to play a specially crafted SWF file:
Security bypass -- CVE-2018-12825
External References:
https://helpx.adobe.com/security/products/flash-player/apsb18-25.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:2435 https://access.redhat.com/errata/RHSA-2018:2435
Bugzilla
CVE-2018-12828 flash-plugin: Privilege Escalation vulnerability (APSB18-25)
bugzilla·2018-08-14·CVSS 9.8
CVE-2018-12828 [CRITICAL] CVE-2018-12828 flash-plugin: Privilege Escalation vulnerability (APSB18-25)
CVE-2018-12828 flash-plugin: Privilege Escalation vulnerability (APSB18-25)
Adobe Security Bulletin APSB18-25 for Adobe Flash Player describes a flaw that can possibly lead to privilege escalation when Flash Player is used to play a specially crafted SWF file:
Use of a component with a known vulnerability -- CVE-2018-12828
External References:
https://helpx.adobe.com/security/products/flash-player/apsb18-25.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2018:2435 https://access.redhat.com/errata/RHSA-2018:2435
http://www.securityfocus.com/bid/104706https://launchpad.support.sap.com/#/notes/2643126https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=497256000http://www.securityfocus.com/bid/104706https://launchpad.support.sap.com/#/notes/2643126https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=497256000
2018-07-10
Published