Medium severity6.1NVD Advisory· Published Feb 14, 2018· Updated Jun 17, 2026
CVE-2018-2364
CVE-2018-2364
Description
SAP CRM WebClient UI 7.01, 7.31, 7.46, 7.47, 7.48, 8.00, 8.01, S4FND 1.02, does not sufficiently validate and/or encode hidden fields, resulting in Cross-Site Scripting (XSS) vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12cpe:2.3:a:sap:customer_relationship_management_webclient_ui:7.01:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:sap:customer_relationship_management_webclient_ui:7.01:*:*:*:*:*:*:*
- cpe:2.3:a:sap:customer_relationship_management_webclient_ui:7.31:*:*:*:*:*:*:*
- cpe:2.3:a:sap:customer_relationship_management_webclient_ui:7.46:*:*:*:*:*:*:*
- cpe:2.3:a:sap:customer_relationship_management_webclient_ui:7.47:*:*:*:*:*:*:*
- cpe:2.3:a:sap:customer_relationship_management_webclient_ui:7.48:*:*:*:*:*:*:*
- cpe:2.3:a:sap:customer_relationship_management_webclient_ui:8.00:*:*:*:*:*:*:*
- cpe:2.3:a:sap:customer_relationship_management_webclient_ui:8.01:*:*:*:*:*:*:*
- Range: 7.01, 7.31, 7.46, 7.47, 7.48, 8.00, 8.01
- SAP SE/S4FNDv5Range: 1.02
- SAP SE/SAP CRM WebClient UIv5Range: 7.01
Patches
Vulnerability mechanics
References
3- www.securityfocus.com/bid/103002nvdThird Party AdvisoryVDB Entry
- blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/nvdVendor Advisory
- launchpad.support.sap.comnvdPermissions Required
News mentions
0No linked articles in our index yet.