SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
Metrics
Affected Vendors & Products
References
History
Wed, 22 Oct 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 21 Oct 2025 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 29 Jan 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
kev
|
Tue, 28 Jan 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_0
|
cvssV3_1
|
Status: PUBLISHED
Assigner: sap
Published: 2018-03-01T17:00:00.000Z
Updated: 2025-10-21T23:45:56.073Z
Reserved: 2017-12-15T00:00:00.000Z
Link: CVE-2018-2380
Updated: 2024-08-05T04:14:39.708Z
Status : Modified
Published: 2018-03-01T17:29:00.413
Modified: 2025-10-22T00:16:22.873
Link: CVE-2018-2380
No data.