Skip to content
COOEY

EXPOSURES › CVE-2018-2380

CVE-2018-2380

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2018-2380 ↗
⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwareexploited-in-wildunpatched

A path traversal vulnerability in SAP CRM allowed attackers to access sensitive files without authorization, and it's currently being exploited in the wild.

SAP CRM's failure to properly validate user-provided file paths enabled unauthorized access to system files, potentially exposing sensitive data. DIB organizations using SAP CRM must immediately patch this vulnerability to avoid data breaches and potential CMMC compliance failures. Prioritize patching and review file access controls.

Shame score — The vulnerability's active exploitation and potential for data exposure demonstrate a significant failure in secure coding practices and risk management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
SAP faced significant scrutiny for a path traversal vulnerability in its CRM product, which could allow attackers to access unauthorized files or directories. The NVD entry highlights the severity of
cooey ↗ severe-fallout -0.60
SAP faced significant scrutiny for a path traversal vulnerability in its CRM product, which could allow attackers to access unauthorized files or directories. The NVD entry highlights the severity of
"SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users."
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
SAP NS2 Cloud Intelligent Enterprise
SAP National Security Services Inc. (SAP NS2)
Authorized
SAP NS2 Secure Node with SuccessFactors Suite - DoD
SAP National Security Services Inc. (SAP NS2)
Authorized