60
CVE-2018-2449
—CVSS 3.0
8.6 high
EPSS
2%p75
Published
()
Modified
Description
SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid repository user. This is an unauthenticated functionality that you can use on windows machines to do SMB relaying.
- Vendors
- sap
- Products
- supplier relationship management mdm catalog
- Weakness
- CWE-287
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H