{
  "id": "CVE-2018-2380",
  "url": "https://spydr.io/cve/CVE-2018-2380",
  "published": "2018-03-01T17:29:00.413Z",
  "modified": "2026-06-17T01:55:36.227Z",
  "score": 6.6,
  "severity": "medium",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L",
  "score_source": "NVD",
  "epss": 0.28934,
  "epss_percentile": 0.98116,
  "exploited": true,
  "kev": {
    "added": "2021-11-03",
    "due": "2022-05-03",
    "action": "Apply updates per vendor instructions.",
    "ransomware": "Known",
    "name": "SAP Customer Relationship Management (CRM) Path Traversal Vulnerability",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2018-2380"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "SAP SE"
  ],
  "products": [
    "SAP SE SAP CRM"
  ],
  "cwes": [
    "CWE-22"
  ],
  "description": "SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing \"traverse to parent directory\" are passed through to the file APIs.",
  "status": "Analyzed",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 6.6,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/103001",
      "tags": [
        "Broken Link",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/",
      "tags": [
        "Vendor Advisory"
      ]
    },
    {
      "url": "https://github.com/erpscanteam/CVE-2018-2380",
      "tags": [
        "Exploit",
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://launchpad.support.sap.com/#/notes/2547431",
      "tags": [
        "Permissions Required"
      ]
    },
    {
      "url": "https://www.exploit-db.com/exploits/44292/",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-2380",
      "tags": [
        "US Government Resource"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2018-2380",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
