CVE-2018-2424 describes an input validation vulnerability in SAP UI5, SAP Hana Database, and related SAP UI components, allowing malicious JavaScript to be injected into the DOM. This cross-site scripting (XSS) flaw carries a CVSS v3 score of 7.5 (HIGH), indicating a network-exploitable vulnerability with low attack complexity that could lead to high confidentiality impact by stealing user information. While the vulnerability is not listed on the KEV catalog and no public exploit code is readily available, it has garnered some community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.00CPE matchmatch criteria | cpe:2.3:a:sap:hana_database:1.00:*:*:*:*:*:*:* | ||
2.00CPE matchmatch criteria | cpe:2.3:a:sap:hana_database:2.00:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:a:sap:ui:2.0:*:*:*:*:netweaver_7.0:*:* | ||
7.40CPE matchmatch criteria | cpe:2.3:a:sap:ui:7.40:*:*:*:*:*:*:* | ||
7.50CPE matchmatch criteria | cpe:2.3:a:sap:ui:7.50:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.