CVE Published: 01/03/2018 |
CVE Updated: 05/08/2024 |
CVE Year: 2018 Source: sap |
Vendor: SAP SE |
Product: SAP CRM Status : PUBLISHED
CVE-2018-2380 Description
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.