VYPR
High severity7.2NVD Advisory· Published Nov 13, 2018· Updated Jun 17, 2026

CVE-2018-2478

CVE-2018-2478

Description

An attacker can use specially crafted inputs to execute commands on the host of a TREX / BWA installation, SAP Basis, versions: 7.0 to 7.02, 7.10 to 7.11, 7.30, 7.31, 7.40 and 7.50 to 7.53. Not all commands are possible, only those that can be executed by the adm user. The commands executed depend upon the privileges of the adm user.

Affected products

7
  • SAP/BASIS5 versions
    cpe:2.3:a:sap:basis:*:*:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:sap:basis:*:*:*:*:*:*:*:*range: >=7.0,<=7.02
    • cpe:2.3:a:sap:basis:7.30:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:basis:7.31:*:*:*:*:*:*:*
    • cpe:2.3:a:sap:basis:7.40:*:*:*:*:*:*:*
    • (no CPE)range: 7.0 to 7.02, 7.10 to 7.11, 7.30, 7.31, 7.40 and 7.50 to 7.53
  • SAP/TREX / BWAllm-create
    Range: 7.0 to 7.02, 7.10 to 7.11, 7.30, 7.31, 7.40 and 7.50 to 7.53
  • SAP/SAP Basis (TREX / BWA installation)v5
    Range: = 7.0 to 7.02

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.