VYPR
Medium severity6.1NVD Advisory· Published Feb 14, 2018· Updated Jun 17, 2026

CVE-2018-2364

CVE-2018-2364

Description

SAP CRM WebClient UI 7.01, 7.31, 7.46, 7.47, 7.48, 8.00, 8.01, S4FND 1.02, does not sufficiently validate and/or encode hidden fields, resulting in Cross-Site Scripting (XSS) vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

12
  • cpe:2.3:a:sap:customer_relationship_management_webclient_ui:7.01:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:sap:customer_relationship_management_webclient_ui:7.01:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:customer_relationship_management_webclient_ui:7.31:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:customer_relationship_management_webclient_ui:7.46:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:customer_relationship_management_webclient_ui:7.47:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:customer_relationship_management_webclient_ui:7.48:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:customer_relationship_management_webclient_ui:8.00:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:customer_relationship_management_webclient_ui:8.01:*:*:*:*:*:*:*
  • SAP/S4FND2 versions
    cpe:2.3:a:sap:s4fnd:1.02:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sap:s4fnd:1.02:*:*:*:*:*:*:*
    • (no CPE)range: 1.02
  • Range: 7.01, 7.31, 7.46, 7.47, 7.48, 8.00, 8.01
  • SAP SE/S4FNDv5
    Range: 1.02
  • SAP SE/SAP CRM WebClient UIv5
    Range: 7.01

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.