Remote Code Execution Vulnerability in SAP Fiori Client
CVE-2018-2491
7.8HIGH
Summary
The SAP Fiori Client allows the logging of deep link URLs when the log level is set to 'Debug'. This poses a security risk as if a URL contains malicious JavaScript code, it could execute when the user accesses the log viewer and clicks a hyperlink. Users are advised to update to SAP Fiori Client version 1.11.5 available on Google Play Store to mitigate this vulnerability.
Affected Version(s)
SAP Fiori Client < 1.11.5
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved