PoC Index

CVE-2018-2380

KEV RANSOMWAREMEDIUM 6.6EPSS 28.9%

SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.

CVSS v3.1
6.6 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
CVSS v3.1
6.6 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
CVSS v2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
28.93% chance of exploitation in the next 30 days, 98th percentile
CISA KEV
added 2021-11-03, used in ransomware campaigns
Published
2018-03-01
Updated
2025-10-21

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related