Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-2478

An attacker can use specially crafted inputs to execute commands on the host of a TREX / BWA installation, SAP Basis, versions: 7.0 to 7.02, 7.10 to 7.11, 7.30, 7.31, 7.40 and 7.50 to 7.53. Not all commands are possible, only those that can be executed by the <sid>adm user. The commands executed depend upon the privileges of the <sid>adm user.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 59.1%
CVSS Severity
CVSS v3 Score 7.2
CVSS v2 Score 6.5
Products affected by CVE-2018-2478
  • Sap » Basis » Version: 7.0
    cpe:2.3:a:sap:basis:7.0
  • Sap » Basis » Version: 7.00
    cpe:2.3:a:sap:basis:7.00
  • Sap » Basis » Version: 7.01
    cpe:2.3:a:sap:basis:7.01
  • Sap » Basis » Version: 7.02
    cpe:2.3:a:sap:basis:7.02
  • Sap » Basis » Version: 7.10
    cpe:2.3:a:sap:basis:7.10
  • Sap » Basis » Version: 7.11
    cpe:2.3:a:sap:basis:7.11
  • Sap » Basis » Version: 7.30
    cpe:2.3:a:sap:basis:7.30
  • Sap » Basis » Version: 7.31
    cpe:2.3:a:sap:basis:7.31
  • Sap » Basis » Version: 7.40
    cpe:2.3:a:sap:basis:7.40
  • Sap » Basis » Version: 7.50
    cpe:2.3:a:sap:basis:7.50
  • Sap » Basis » Version: 7.51
    cpe:2.3:a:sap:basis:7.51
  • Sap » Basis » Version: 7.52
    cpe:2.3:a:sap:basis:7.52
  • Sap » Basis » Version: 7.53
    cpe:2.3:a:sap:basis:7.53


Contact Us

Shodan ® - All rights reserved