cve/2018/CVE-2018-2478.md

19 lines
970 B
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2018-2478](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-2478)
![](https://img.shields.io/static/v1?label=Product&message=SAP%20Basis%20(TREX%20%2F%20BWA%20installation)&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=%3D7.0%20to%207.02%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=Other&color=brighgreen)
### Description
An attacker can use specially crafted inputs to execute commands on the host of a TREX / BWA installation, SAP Basis, versions: 7.0 to 7.02, 7.10 to 7.11, 7.30, 7.31, 7.40 and 7.50 to 7.53. Not all commands are possible, only those that can be executed by the <sid>adm user. The commands executed depend upon the privileges of the <sid>adm user.
### POC
#### Reference
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=503809832
2024-06-09 00:33:16 +00:00
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=503809832
2024-05-26 14:27:05 +02:00
#### Github
No PoCs found on GitHub currently.