CVE-2018-2450

CWE-89SQL Injection3 documents3 sources
Severity
7.2HIGH
EPSS
0.6%
top 31.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 14
Latest updateMay 14

Description

SAP MaxDB (liveCache), versions 7.8 and 7.9, allows an attacker who gets DBM operator privileges to execute crafted database queries and therefore read, modify or delete sensitive data from database.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

Affected Packages2 packages

CVEListV5sap/sap_maxdb_(livecache)7.8, 7.9+1
NVDsap/maxdb7.8, 7.9+1

🔴Vulnerability Details

2
GHSA
GHSA-wc5w-8r86-c387: SAP MaxDB (liveCache), versions 72022-05-14
CVEList
CVE-2018-2450: SAP MaxDB (liveCache), versions 72018-08-14
CVE-2018-2450 (HIGH CVSS 7.2) | SAP MaxDB (liveCache) | cvebase.io