4.3
CVSSv2

CVE-2018-2415

Published: 09/05/2018 Updated: 09/10/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 4.7 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

SAP NetWeaver Application Server Java Web Container and HTTP Service (Engine API, from 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; J2EE Engine Server Core 7.11, 7.30, 7.31, 7.40, 7.50) do not sufficiently encode user controlled inputs, resulting in a content spoofing vulnerability when error pages are displayed.

Vulnerable Product Search on Vulmon Subscribe to Product

sap netweaver java web container and http service engine 7.50

sap netweaver java web container and http service engine 7.10

sap netweaver java web container and http service engine 7.11

sap netweaver java web container and http service engine 7.30

sap netweaver java web container and http service engine 7.31

sap netweaver java web container and http service engine 7.40

sap j2ee engine server core 7.30

sap j2ee engine server core 7.31

sap j2ee engine server core 7.40

sap j2ee engine server core 7.50

sap j2ee engine server core 7.11