cbcvebase.
CVE-2018-2488
published 2018-11-13

CVE-2018-2488: It is possible for a malware application installed on an Android device to send local push notifications with an empty message to SAP Fiori Client and cause…

PriorityP432high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
0.79%
51.9th percentile
It is possible for a malware application installed on an Android device to send local push notifications with an empty message to SAP Fiori Client and cause the application to crash. SAP Fiori Client version 1.11.5 in Google Play store addresses these issues and users must update to that version.

Affected

2 ranges
VendorProductVersion rangeFixed in
sapfiori_client< 1.11.51.11.5
sapsap_fiori_client< 1.11.51.11.5

CVSS provenance

nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.