← Back to browse · API

CVE-2018-2380

Severity
MEDIUM
CVSS
6.6
EPSS
0.28892
Risk score
61.51
CISA KEV
Yes
PoC
No
Published
2018-03-01
Modified
2025-10-21
First seen
2026-08-07
Aliases
EUVD-2018-14235, GHSA-22J7-69M5-2PQH
Products
SAP SE:SAP CRM 7.01, SAP SE:SAP CRM 7.02, SAP SE:SAP CRM 7.30, SAP SE:SAP CRM 7.31, SAP SE:SAP CRM 7.33, SAP SE:SAP CRM 7.54, SAP:Customer Relationship Management (CRM)
Sources
euvd EUVD-2018-14235
cisa.gov CVE-2018-2380

Description

SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.

References