Insufficient Path Validation in SAP BASIS
CVE-2018-2367
8.8HIGH
What is CVE-2018-2367?
The ABAP File Interface in SAP BASIS versions 7.00 to 7.52 contains a vulnerability that arises from inadequate validation of user-supplied path information. This flaw allows attackers to manipulate file paths and potentially access sensitive files through unauthorized traversal commands. Proper configuration and patching are essential to mitigate this risk.
Affected Version(s)
SAP BASIS (ABAP File Interface) from 7.00 to 7.02
SAP BASIS (ABAP File Interface) from 7.10 to 7.11
SAP BASIS (ABAP File Interface) 7.30