EXPOSURES › CVE-2018-2380
CVE-2018-2380
CRITICAL ⌖ ON CISA KEV · EXPLOITEDA path traversal vulnerability in SAP CRM allowed attackers to access sensitive files without authorization, and it's currently being exploited in the wild.
SAP CRM's failure to properly validate user-provided file paths enabled unauthorized access to system files, potentially exposing sensitive data. DIB organizations using SAP CRM must immediately patch this vulnerability to avoid data breaches and potential CMMC compliance failures. Prioritize patching and review file access controls.
Shame score — The vulnerability's active exploitation and potential for data exposure demonstrate a significant failure in secure coding practices and risk management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users.
"SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users."
| PRODUCT | STATUS |
|---|---|
| SAP NS2 Cloud Intelligent Enterprise SAP National Security Services Inc. (SAP NS2) |
Authorized |
| SAP NS2 Secure Node with SuccessFactors Suite - DoD SAP National Security Services Inc. (SAP NS2) |
Authorized |