CVE-2018-2364 vulnerability in SAP Products
Published on February 14, 2018
SAP CRM WebClient UI 7.01, 7.31, 7.46, 7.47, 7.48, 8.00, 8.01, S4FND 1.02, does not sufficiently validate and/or encode hidden fields, resulting in Cross-Site Scripting (XSS) vulnerability.
Products Associated with CVE-2018-2364
stack.watch emails you whenever new vulnerabilities are published in SAP Customer Relationship Management Webclient Ui or SAP S4fnd. Just hit a watch button to start following.
Affected Versions
SAP SE SAP CRM WebClient UI:- Version 7.01 is affected.
- Version 7.31 is affected.
- Version 7.46 is affected.
- Version 7.47 is affected.
- Version 7.48 is affected.
- Version 8.00 is affected.
- Version 8.01 is affected.
- Version 1.02 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.