CVE-2018-2468 describes an information disclosure vulnerability in SAP Adaptive Server Enterprise (ASE) versions 15.7 and 16.0, where the backup server can expose restricted information under specific conditions. This is a high-severity vulnerability with a CVSS score of 7.5, indicating that an unauthenticated attacker can remotely access sensitive data without user interaction. While the EPSS score and KEV status suggest low current exploitation risk, its FAUCET score of 50/100 indicates moderate overall risk. There is no public exploit code available, and community discussion and media coverage are minimal, with only one article from SecurityWeek mentioning it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
15.7CPE matchmatch criteria | cpe:2.3:a:sap:adaptive_server_enterprise:15.7:*:*:*:*:*:*:* | ||
16.0CPE matchmatch criteria | cpe:2.3:a:sap:adaptive_server_enterprise:16.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.