ID

VAR-201806-1433


CVE

CVE-2018-2424


TITLE

SAP UI5 Input validation vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2018-006576

DESCRIPTION

SAP UI5 did not validate user input before adding it to the DOM structure. This may lead to malicious user-provided JavaScript code being added to the DOM that could steal user information. Software components affected are: SAP Hana Database 1.00, 2.00; SAP UI5 1.00; SAP UI5 (Java) 7.30, 7.31, 7.40, 7,50; SAP UI 7.40, 7.50, 7.51, 7.52, and version 2.0 of SAP UI for SAP NetWeaver 7.00. SAP UI5 is prone to an cross-site scripting vulnerability because it fails to properly sanitize user-supplied input. Remote attackers can exploit this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and launch other attacks

Trust: 1.89

sources: NVD: CVE-2018-2424 // JVNDB: JVNDB-2018-006576 // BID: 104459

AFFECTED PRODUCTS

vendor:sapmodel:uiscope:eqversion:7.52

Trust: 2.7

vendor:sapmodel:uiscope:eqversion:7.51

Trust: 2.7

vendor:sapmodel:uiscope:eqversion:7.50

Trust: 2.7

vendor:sapmodel:uiscope:eqversion:7.40

Trust: 2.7

vendor:sapmodel:hana databasescope:eqversion:1.00

Trust: 2.4

vendor:sapmodel:uiscope:eqversion:2.0

Trust: 2.1

vendor:sapmodel:ui5scope:eqversion:1.00

Trust: 1.9

vendor:sapmodel:hana databasescope:eqversion:2.00

Trust: 1.8

vendor:sapmodel:ui5 javascope:eqversion:7.50

Trust: 1.6

vendor:sapmodel:ui5 javascope:eqversion:7.31

Trust: 1.6

vendor:sapmodel:ui5 javascope:eqversion:7.30

Trust: 1.6

vendor:sapmodel:ui5 javascope:eqversion:7.40

Trust: 1.6

vendor:sapmodel:uiscope:eqversion:5 1.00

Trust: 0.8

vendor:sapmodel:uiscope:eqversion:5 java 7

Trust: 0.8

vendor:sapmodel:uiscope:eqversion:50

Trust: 0.8

vendor:sapmodel:uiscope:eqversion:5 java 7.30

Trust: 0.8

vendor:sapmodel:uiscope:eqversion:5 java 7.31

Trust: 0.8

vendor:sapmodel:uiscope:eqversion:5 java 7.40

Trust: 0.8

vendor:sapmodel:ui5scope:eqversion:7.50

Trust: 0.3

vendor:sapmodel:ui5scope:eqversion:7.40

Trust: 0.3

vendor:sapmodel:ui5scope:eqversion:7.31

Trust: 0.3

vendor:sapmodel:ui5scope:eqversion:7.30

Trust: 0.3

vendor:sapmodel:netweaverscope:eqversion:7.0

Trust: 0.3

vendor:sapmodel:hana dbscope:eqversion:2.00

Trust: 0.3

vendor:sapmodel:hana dbscope:eqversion:1.00

Trust: 0.3

sources: BID: 104459 // JVNDB: JVNDB-2018-006576 // CNNVD: CNNVD-201806-735 // NVD: CVE-2018-2424

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-2424
value: HIGH

Trust: 1.0

cna@sap.com: CVE-2018-2424
value: CRITICAL

Trust: 1.0

NVD: CVE-2018-2424
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201806-735
value: HIGH

Trust: 0.6

nvd@nist.gov: CVE-2018-2424
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:P/I:N/A:N
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

nvd@nist.gov: CVE-2018-2424
baseSeverity: HIGH
baseScore: 7.5
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: NONE
availabilityImpact: NONE
exploitabilityScore: 3.9
impactScore: 3.6
version: 3.0

Trust: 1.8

cna@sap.com: CVE-2018-2424
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 1.0

sources: JVNDB: JVNDB-2018-006576 // CNNVD: CNNVD-201806-735 // NVD: CVE-2018-2424 // NVD: CVE-2018-2424

PROBLEMTYPE DATA

problemtype:CWE-20

Trust: 1.8

sources: JVNDB: JVNDB-2018-006576 // NVD: CVE-2018-2424

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201806-735

TYPE

Input Validation Error

Trust: 0.9

sources: BID: 104459 // CNNVD: CNNVD-201806-735

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-006576

PATCH

title:June 2018 Security Releasesurl:https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=495289255

Trust: 0.8

title:SAP Hana DB , UI5 and UI Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=80900

Trust: 0.6

sources: JVNDB: JVNDB-2018-006576 // CNNVD: CNNVD-201806-735

EXTERNAL IDS

db:NVDid:CVE-2018-2424

Trust: 2.7

db:BIDid:104459

Trust: 1.9

db:JVNDBid:JVNDB-2018-006576

Trust: 0.8

db:CNNVDid:CNNVD-201806-735

Trust: 0.6

sources: BID: 104459 // JVNDB: JVNDB-2018-006576 // CNNVD: CNNVD-201806-735 // NVD: CVE-2018-2424

REFERENCES

url:https://launchpad.support.sap.com/#/notes/2538856

Trust: 1.9

url:https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageid=495289255

Trust: 1.9

url:http://www.securityfocus.com/bid/104459

Trust: 1.6

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-2424

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-2424

Trust: 0.8

url:http://www.sap.com

Trust: 0.3

sources: BID: 104459 // JVNDB: JVNDB-2018-006576 // CNNVD: CNNVD-201806-735 // NVD: CVE-2018-2424

CREDITS

The vendor reported this issue.

Trust: 0.3

sources: BID: 104459

SOURCES

db:BIDid:104459
db:JVNDBid:JVNDB-2018-006576
db:CNNVDid:CNNVD-201806-735
db:NVDid:CVE-2018-2424

LAST UPDATE DATE

2024-11-23T23:08:38.602000+00:00


SOURCES UPDATE DATE

db:BIDid:104459date:2018-06-12T00:00:00
db:JVNDBid:JVNDB-2018-006576date:2018-08-24T00:00:00
db:CNNVDid:CNNVD-201806-735date:2019-10-17T00:00:00
db:NVDid:CVE-2018-2424date:2024-11-21T04:03:47.570

SOURCES RELEASE DATE

db:BIDid:104459date:2018-06-12T00:00:00
db:JVNDBid:JVNDB-2018-006576date:2018-08-24T00:00:00
db:CNNVDid:CNNVD-201806-735date:2018-06-13T00:00:00
db:NVDid:CVE-2018-2424date:2018-06-12T15:29:00.307