Remote Code Execution Vulnerability in SAP Fiori Client
CVE-2018-2491
7.8HIGH
What is CVE-2018-2491?
The SAP Fiori Client allows the logging of deep link URLs when the log level is set to 'Debug'. This poses a security risk as if a URL contains malicious JavaScript code, it could execute when the user accesses the log viewer and clicks a hyperlink. Users are advised to update to SAP Fiori Client version 1.11.5 available on Google Play Store to mitigate this vulnerability.
Affected Version(s)
SAP Fiori Client < 1.11.5