Authentication Bypass in SAP SRM MDM Catalog by SAP
CVE-2018-2449
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 14 August 2018
What is CVE-2018-2449?
The import functionality in specific versions of SAP SRM MDM Catalog lacking proper authentication checks for repository users poses a significant threat. This vulnerability allows unauthorized actors to exploit this unauthenticated feature on Windows systems, enabling SMB relaying attacks that could result in unauthorized access to sensitive data and system resources.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
SAP Supplier Relationship Management Master Data Management Catalog 3.73
SAP Supplier Relationship Management Master Data Management Catalog 7.31
SAP Supplier Relationship Management Master Data Management Catalog 7.32
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved