cbcvebase.
CVE-2018-2494
published 2018-12-11

CVE-2018-2494: Necessary authorization checks for an authenticated user, resulting in escalation of privileges, have been fixed in SAP Basis AS ABAP of SAP NetWeaver 700 to…

PriorityP337high8CVSS 3.0
AVNACLPRLUIRSUCHIHAH
EPSS
0.76%
50.9th percentile
Necessary authorization checks for an authenticated user, resulting in escalation of privileges, have been fixed in SAP Basis AS ABAP of SAP NetWeaver 700 to 750, from 750 onwards delivered as ABAP Platform.

Affected

10 ranges
VendorProductVersion rangeFixed in
sapbusiness_application_software_integrated_solution
sapbusiness_application_software_integrated_solution
sapbusiness_application_software_integrated_solution7.00 – 7.02
sapbusiness_application_software_integrated_solution7.10 – 7.30
sapbusiness_application_software_integrated_solution7.50 – 7.53
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis
sapsap_basis

CVSS provenance

nvdv3.08.0HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.