CVE-2018-2370
N/A
N/A
Summary
Server Side Request Forgery (SSRF) vulnerability in SAP Central Management Console, BI Launchpad and Fiori BI Launchpad, 4.10, from 4.20, from 4.30, could allow a malicious user to use common techniques to determine which ports are in use on the backend server.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SAP SE | SAP BI Launchpad | 4.00 | affected |
| SAP SE | SAP BI Launchpad | from 4.20 | affected |
| SAP SE | SAP BI Launchpad | from 4.30 | affected |
Weaknesses
- Server Side Request Forgery (SSRF)
ADP Enrichment
CVE Program Container
Additional References
- https://launchpad.support.sap.com/#/notes/2493727
- http://www.securityfocus.com/bid/102998
- https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/
References
- https://launchpad.support.sap.com/#/notes/2493727
- http://www.securityfocus.com/bid/102998
- https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.