### [CVE-2018-2370](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-2370) ![](https://img.shields.io/static/v1?label=Product&message=SAP%20BI%20Launchpad&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=%3D%204.00%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Server%20Side%20Request%20Forgery%20(SSRF)&color=brighgreen) ### Description Server Side Request Forgery (SSRF) vulnerability in SAP Central Management Console, BI Launchpad and Fiori BI Launchpad, 4.10, from 4.20, from 4.30, could allow a malicious user to use common techniques to determine which ports are in use on the backend server. ### POC #### Reference - https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/ - https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/ #### Github No PoCs found on GitHub currently.