Improper Session Management in SAP Cloud Platform by SAP
CVE-2018-2409

6.3MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
10 April 2018

Summary

This vulnerability arises from flawed session management practices in SAP Cloud Platform 2.0, specifically in the Connectivity Service and Cloud Connector components. Under specific conditions, applications built on this platform may inadvertently display or allow modification of another user's data, posing a significant risk to user privacy and data integrity. It is crucial for users and organizations leveraging this platform to assess their current implementations and apply necessary patches or security configurations to mitigate potential impacts.

Affected Version(s)

SAP Cloud Platform Connector 2.0

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.