Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-2449

Опубликовано: 14 авг. 2018
Источник: nvd
CVSS3: 8.6
CVSS2: 7.5
EPSS Низкий

Описание

SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid repository user. This is an unauthenticated functionality that you can use on windows machines to do SMB relaying.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:sap:supplier_relationship_management_mdm_catalog:3.73:*:*:*:*:*:*:*
cpe:2.3:a:sap:supplier_relationship_management_mdm_catalog:7.31:*:*:*:*:*:*:*
cpe:2.3:a:sap:supplier_relationship_management_mdm_catalog:7.32:*:*:*:*:*:*:*

EPSS

Процентиль: 79%
0.01304
Низкий

8.6 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 8.6
github
больше 3 лет назад

SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid repository user. This is an unauthenticated functionality that you can use on windows machines to do SMB relaying.

EPSS

Процентиль: 79%
0.01304
Низкий

8.6 High

CVSS3

7.5 High

CVSS2

Дефекты

CWE-287