### [CVE-2018-2478](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-2478) ![](https://img.shields.io/static/v1?label=Product&message=SAP%20Basis%20(TREX%20%2F%20BWA%20installation)&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=%3D7.0%20to%207.02%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Other&color=brighgreen) ### Description An attacker can use specially crafted inputs to execute commands on the host of a TREX / BWA installation, SAP Basis, versions: 7.0 to 7.02, 7.10 to 7.11, 7.30, 7.31, 7.40 and 7.50 to 7.53. Not all commands are possible, only those that can be executed by the adm user. The commands executed depend upon the privileges of the adm user. ### POC #### Reference - https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=503809832 - https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=503809832 #### Github No PoCs found on GitHub currently.