VYPR
Unrated severityNVD Advisory· Published Dec 11, 2018· Updated Aug 5, 2024

CVE-2018-2486

CVE-2018-2486

Description

SAP Marketing (UICUAN (1.20, 1.30, 1.40), SAPSCORE (1.13, 1.14)) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

Affected products

5
  • SAP/SAP Marketingllm-create3 versions
    UICUAN: 1.20,1.30,1.40; SAPSCORE: 1.13,1.14+ 2 more
    • (no CPE)range: UICUAN: 1.20,1.30,1.40; SAPSCORE: 1.13,1.14
    • (no CPE)range: = 1.13
    • (no CPE)range: = 1.20
  • SAP/UICUANllm-create
    Range: 1.20, 1.30, 1.40
  • SAP/SAPSCOREllm-create
    Range: 1.13, 1.14

Patches

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.