VYPR
Medium severity5.3NVD Advisory· Published Jun 12, 2018· Updated Jun 17, 2026

CVE-2018-2428

CVE-2018-2428

Description

Under certain conditions SAP UI5 Handler allows an attacker to access information which would otherwise be restricted. Software components affected are: SAP Infrastructure 1.0, SAP UI 7.4, 7.5, 7.51, 7.52 and version 2.0 of SAP UI for SAP NetWeaver 7.00.

Affected products

12
  • cpe:2.3:a:sap:infrastructure:1.0:*:*:*:*:*:*:*
  • SAP/UI6 versions
    cpe:2.3:a:sap:ui:2.0:*:*:*:*:netweaver_7.0:*:*+ 5 more
    • cpe:2.3:a:sap:ui:2.0:*:*:*:*:netweaver_7.0:*:*
    • cpe:2.3:a:sap:ui:7.4:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:ui:7.51:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:ui:7.52:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:ui:7.5:*:*:*:*:*:*:*
    • (no CPE)range: >=7.4, <=7.52
  • Range: =1.0
  • SAP SE/SAP Infrastructurev5
    Range: 1.0
  • SAP SE/SAP UIv5
    Range: 7.4
  • SAP SE/SAP UI for SAP NetWeaver 7.00v5
    Range: 2.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.