Remote Code Execution Vulnerability in SAP Fiori Client
CVE-2018-2491

7.8HIGH

Key Information:

Vendor
SAP
Vendor
CVE Published:
13 November 2018

Summary

The SAP Fiori Client allows the logging of deep link URLs when the log level is set to 'Debug'. This poses a security risk as if a URL contains malicious JavaScript code, it could execute when the user accesses the log viewer and clicks a hyperlink. Users are advised to update to SAP Fiori Client version 1.11.5 available on Google Play Store to mitigate this vulnerability.

Affected Version(s)

SAP Fiori Client < 1.11.5

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.