CVE-2018-2380
SAP SE SAP CRM
Published 1 Mar 2018 · updated 17 Jun 2026 · Analyzed
6.6 Medium · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Nov 2021, with a remediation deadline of 3 May 2022 for US federal agencies. It has been used in ransomware campaigns.
Required action: Apply updates per vendor instructions.
Description
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
References
- www.securityfocus.com/bid/103001 · Broken Link, Third Party Advisory, VDB Entry
- blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/ · Vendor Advisory
- github.com/erpscanteam/CVE-2018-2380 · Exploit, Third Party Advisory
- launchpad.support.sap.com/#/notes/2547431 · Permissions Required
- www.exploit-db.com/exploits/44292/ · Exploit, Third Party Advisory, VDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-2380 · US Government Resource