Junglewise Threat Intelligence

CVE-2018-2380: SAP Customer Relationship Management (CRM) Path Traversal Vulnerability

CVE-2018-2380 · Severity: critical · CVSS 6.6 · Exploited in the wild · Published 2021-11-03

Vendors: SAP.

Executive brief

SAP Customer Relationship Management (CRM) contains a path traversal vulnerability due to insufficient validation of user-provided path information. Attackers can use "traverse to parent directory" characters to bypass directory restrictions via file APIs.

Affected products

  • SAP Customer Relationship Management (CRM) 7.01, 7.02, 7.30, 7.31, 7.33, 7.54

Timeline

  • 2018-02-13: advisory: SAP Security Patch Day February 2018
  • 2018-03-01: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog