Local Notification Crash Vulnerability in SAP Fiori Client for Android
CVE-2018-2488

7.8HIGH

Key Information:

Vendor
SAP
Vendor
CVE Published:
13 November 2018

Summary

A malware application on an Android device can exploit the local push notification feature of the SAP Fiori Client, resulting in the application crashing when it attempts to process empty messages. Users must upgrade to the latest version, 1.11.5, available on the Google Play store to safeguard against this exploit.

Affected Version(s)

SAP Fiori Client < 1.11.5

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.