CVE Database
/

CVE-2018-2491

Back to search

CVE-2018-2491

Published: Nov 13, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

When opening a deep link URL in SAP Fiori Client with log level set to "Debug", the client application logs the URL to the log file. If this URL contains malicious JavaScript code it can eventually run inside the built-in log viewer of the application in case user opens the viewer and taps on the hyperlink in the viewer. SAP Fiori Client version 1.11.5 in Google Play store addresses these issues and users must update to that version.

VendorProductVersions

SAP

SAP Fiori Client

affected
< 1.11.5

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now