Vulnerability Details CVE-2018-2366
SAP Business Process Automation (BPA) By Redwood, 9.0, 9.1, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 73.9%
CVSS Severity
CVSS v3 Score 4.3
CVSS v2 Score 4.0
Products affected by CVE-2018-2366
-
cpe:2.3:a:redwood:sap_business_process_automation:9.0
-
cpe:2.3:a:redwood:sap_business_process_automation:9.1