CVE Database
/

CVE-2018-2478

Back to search

CVE-2018-2478

Published: Nov 13, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

An attacker can use specially crafted inputs to execute commands on the host of a TREX / BWA installation, SAP Basis, versions: 7.0 to 7.02, 7.10 to 7.11, 7.30, 7.31, 7.40 and 7.50 to 7.53. Not all commands are possible, only those that can be executed by the <sid>adm user. The commands executed depend upon the privileges of the <sid>adm user.

VendorProductVersions

SAP

SAP Basis (TREX / BWA installation)

affected
= 7.0 to 7.02
affected
= 7.10 to 7.11
affected
= 7.30
affected
= 7.31
affected
= 7.40

+1 more versions

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now