VYPR
Medium severity5.3NVD Advisory· Published Aug 14, 2018· Updated Jun 17, 2026

CVE-2018-2448

CVE-2018-2448

Description

Under certain conditions SAP SRM-MDM (CATALOG versions 3.0, 7.01, 7.02) utilities functionality allows an attacker to access information of user existence which would otherwise be restricted.

Affected products

5
  • cpe:2.3:a:sap:supplier_relationship_management_mdm_catalog:3.0:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:sap:supplier_relationship_management_mdm_catalog:3.0:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:supplier_relationship_management_mdm_catalog:7.01:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:supplier_relationship_management_mdm_catalog:7.02:*:*:*:*:*:*:*
  • SAP/SRM-MDMllm-create
    Range: 3.0, 7.01, 7.02
  • Range: 3.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.