VYPR
Critical severity9.8NVD Advisory· Published Jun 12, 2018· Updated Jun 17, 2026

CVE-2018-2424

CVE-2018-2424

Description

SAP UI5 did not validate user input before adding it to the DOM structure. This may lead to malicious user-provided JavaScript code being added to the DOM that could steal user information. Software components affected are: SAP Hana Database 1.00, 2.00; SAP UI5 1.00; SAP UI5 (Java) 7.30, 7.31, 7.40, 7,50; SAP UI 7.40, 7.50, 7.51, 7.52, and version 2.0 of SAP UI for SAP NetWeaver 7.00

Affected products

20
  • SAP/Hana Database3 versions
    cpe:2.3:a:sap:hana_database:1.00:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:sap:hana_database:1.00:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:hana_database:2.00:*:*:*:*:*:*:*
    • (no CPE)range: 1.00, 2.00
  • SAP/UI52 versions
    cpe:2.3:a:sap:ui5:1.00:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sap:ui5:1.00:*:*:*:*:*:*:*
    • (no CPE)range: 1.00
  • SAP/Ui5 Java4 versions
    cpe:2.3:a:sap:ui5_java:7.30:*:*:*:*:*:*:*+ 3 more
    • cpe:2.3:a:sap:ui5_java:7.30:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:ui5_java:7.31:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:ui5_java:7.40:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:ui5_java:7.50:*:*:*:*:*:*:*
  • SAP/UI6 versions
    cpe:2.3:a:sap:ui:2.0:*:*:*:*:netweaver_7.0:*:*+ 5 more
    • cpe:2.3:a:sap:ui:2.0:*:*:*:*:netweaver_7.0:*:*
    • cpe:2.3:a:sap:ui:7.40:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:ui:7.50:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:ui:7.51:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:ui:7.52:*:*:*:*:*:*:*
    • (no CPE)range: 7.40, 7.50, 7.51, 7.52
  • SAP SE/SAP HANA Databasev5
    Range: 1.0
  • SAP SE/SAP UIv5
    Range: 7.40
  • SAP SE/SAP UI for SAP NetWeaver 7.00v5
    Range: 2.0
  • SAP SE/SAP UI5v5
    Range: 1.0
  • SAP SE/SAP UI5(Java)v5
    Range: 7.3

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.