### [CVE-2018-2381](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-2381) ![](https://img.shields.io/static/v1?label=Product&message=SAP%20ERP%20Financials%20Information%20System&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=%3D%202.00%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Missing%20Authorization%20Check&color=brighgreen) ### Description SAP ERP Financials Information System (SAP_APPL 6.00, 6.02, 6.03, 6.04, 6.05, 6.06, 6.16; SAP_FIN 6.17, 6.18, 7.00, 7.20, 7.30 S4CORE 1.00, 1.01, 1.02) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. ### POC #### Reference - https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/ - https://blogs.sap.com/2018/02/13/sap-security-patch-day-february-2018/ #### Github No PoCs found on GitHub currently.