CVE Published: 14/08/2018 |
CVE Updated: 05/08/2024 |
CVE Year: 2018 Source: sap |
Vendor: SAP |
Product: SAP Supplier Relationship Management Master Data Management Catalog Status : PUBLISHED
CVE-2018-2449 Description
SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid repository user. This is an unauthenticated functionality that you can use on windows machines to do SMB relaying.