High severity7.8NVD Advisory· Published Nov 13, 2018· Updated Jun 17, 2026
CVE-2018-2488
CVE-2018-2488
Description
It is possible for a malware application installed on an Android device to send local push notifications with an empty message to SAP Fiori Client and cause the application to crash. SAP Fiori Client version 1.11.5 in Google Play store addresses these issues and users must update to that version.
Affected products
3cpe:2.3:a:sap:fiori_client:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:sap:fiori_client:*:*:*:*:*:*:*:*range: <1.11.5
- (no CPE)range: = 1.11.5
- (no CPE)range: < 1.11.5
Patches
Vulnerability mechanics
References
2- launchpad.support.sap.comnvdPermissions RequiredVendor Advisory
- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
News mentions
0No linked articles in our index yet.