SAP NetWeaver Knowledge Management Vulnerability in XMLForms
CVE-2018-2477
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 13 November 2018
What is CVE-2018-2477?
The Knowledge Management component, specifically XMLForms, in SAP NetWeaver versions 7.30, 7.31, 7.40, and 7.50, fails to properly validate XML documents that are accepted from untrusted sources. This oversight can lead to potential security risks, as malicious XML data may be processed without sufficient checks, potentially compromising the system. Organizations using these versions should implement appropriate security measures and monitor SAP's guidance for any updates or patches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Knowledge Management (XMLForms) in SAP NetWeaver = 7.30 = 7.30
Knowledge Management (XMLForms) in SAP NetWeaver = 7.31 = 7.31
Knowledge Management (XMLForms) in SAP NetWeaver = 7.40 = 7.40
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved