VYPR
Unrated severityCISA KEVNVD Advisory· Published Mar 1, 2018· Updated Oct 21, 2025

CVE-2018-2380

CVE-2018-2380

Description

SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.

Affected products

1
  • SAP SE/SAP CRMv5
    Range: 7.01

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.