Medium severity4.7NVD Advisory· Published May 9, 2018· Updated Jun 17, 2026
CVE-2018-2415
CVE-2018-2415
Description
SAP NetWeaver Application Server Java Web Container and HTTP Service (Engine API, from 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; J2EE Engine Server Core 7.11, 7.30, 7.31, 7.40, 7.50) do not sufficiently encode user controlled inputs, resulting in a content spoofing vulnerability when error pages are displayed.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: 7.11, 7.30, 7.31, 7.40, 7.50
- Range: 7.10, 7.11, 7.30, 7.31, 7.40, 7.50
- SAP SE/SAP NetWeaver Application Server (Engine API)v5Range: from 7.10 to 7.11
- SAP SE/SAP NetWeaver Application Server (J2EE Engine Server Core)v5Range: 7.11
Patches
Vulnerability mechanics
References
3- www.securityfocus.com/bid/104130nvdThird Party AdvisoryVDB Entry
- blogs.sap.com/2018/05/08/sap-security-patch-day-may-2018/nvdVendor Advisory
- launchpad.support.sap.comnvdPermissions Required
News mentions
0No linked articles in our index yet.