CVE-2018-2449

SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid repository user. This is an unauthenticated functionality that you can use on windows machines to do SMB relaying.
References
Configurations

Configuration 1

cpe:2.3:a:sap:supplier_relationship_management_mdm_catalog:7.32:*:*:*:*:*:*:*
cpe:2.3:a:sap:supplier_relationship_management_mdm_catalog:7.31:*:*:*:*:*:*:*
cpe:2.3:a:sap:supplier_relationship_management_mdm_catalog:3.73:*:*:*:*:*:*:*

Information

Published : 2018-08-14 04:29

Updated : 2018-10-11 04:49


NVD link : CVE-2018-2449

Mitre link : CVE-2018-2449

Products Affected
No products.
CWE