Vulnerability Details CVE-2018-2486
SAP Marketing (UICUAN (1.20, 1.30, 1.40), SAPSCORE (1.13, 1.14)) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 61.3%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 3.5
Products affected by CVE-2018-2486
-
cpe:2.3:a:sap:marketing_sapscore:1.13
-
cpe:2.3:a:sap:marketing_sapscore:1.14
-
cpe:2.3:a:sap:marketing_uicuan:1.20
-
cpe:2.3:a:sap:marketing_uicuan:1.30
-
cpe:2.3:a:sap:marketing_uicuan:1.40