CVE-2018-2363
Estado: ModificadaAlta (8.8)—
SAP NetWeaver, SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, contains code that allows you to execute arbitrary program code of the user's choice. A malicious user can therefore control the behaviour of the system or can potentially escalate privileges by executing malicious code without legitimate credentials.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 8.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.67%
- Percentil entre todas las CVEs puntuadas: 76
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-94
Referencias
- http://www.securityfocus.com/bid/102449
- https://blogs.sap.com/2018/01/09/sap-security-patch-day-january-2018/
- https://launchpad.support.sap.com/#/notes/1906212
- https://launchpad.support.sap.com/#/notes/2525392
- http://www.securityfocus.com/bid/102449
- https://blogs.sap.com/2018/01/09/sap-security-patch-day-january-2018/
- https://launchpad.support.sap.com/#/notes/1906212
- https://launchpad.support.sap.com/#/notes/2525392
JSON original (NVD)
Mostrar
{
"id": "CVE-2018-2363",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 8.8,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "cna@sap.com",
"affectedData": [
{
"vendor": "SAP SE",
"product": "SAP NetWeaver",
"versions": [
{
"status": "affected",
"version": "7.00"
},
{
"status": "affected",
"version": "7.02"
},
{
"status": "affected",
"version": "7.10"
},
{
"status": "affected",
"version": "7.11"
},
{
"status": "affected",
"version": "7.30"
},
{
"status": "affected",
"version": "7.31"
},
{
"status": "affected",
"version": "7.40"
},
{
"status": "affected",
"version": "7.50"
},
{
"status": "affected",
"version": "7.52"
}
]
}
]
}
],
"published": "2018-01-09T15:29:00.370",
"references": [
{
"url": "http://www.securityfocus.com/bid/102449",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cna@sap.com"
},
{
"url": "https://blogs.sap.com/2018/01/09/sap-security-patch-day-january-2018/",
"tags": [
"Vendor Advisory"
],
"source": "cna@sap.com"
},
{
"url": "https://launchpad.support.sap.com/#/notes/1906212",
"tags": [
"Permissions Required"
],
"source": "cna@sap.com"
},
{
"url": "https://launchpad.support.sap.com/#/notes/2525392",
"tags": [
"Permissions Required"
],
"source": "cna@sap.com"
},
{
"url": "http://www.securityfocus.com/bid/102449",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://blogs.sap.com/2018/01/09/sap-security-patch-day-january-2018/",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://launchpad.support.sap.com/#/notes/1906212",
"tags": [
"Permissions Required"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://launchpad.support.sap.com/#/notes/2525392",
"tags": [
"Permissions Required"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "SAP NetWeaver, SAP BASIS from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, contains code that allows you to execute arbitrary program code of the user's choice. A malicious user can therefore control the behaviour of the system or can potentially escalate privileges by executing malicious code without legitimate credentials."
},
{
"lang": "es",
"value": "SAP NetWeaver y SAP BASIS, desde la versión 7.00 hasta la 7.02, desde la 7.10 a la 7.11, 7.30, 7.31, 7.40 y desde la versión 7.50 a la 7.52, contiene código que permite ejecutar código arbitrario del programa a elección del usuario. Un usuario malicioso puede, por lo tanto, controlar el comportamiento del sistema o escalar privilegios mediante la ejecución de código malicioso sin credenciales legítimas."
}
],
"lastModified": "2026-06-17T01:55:34.453",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sap:netweaver:-:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CB7AAA9B-5209-4419-87DA-8130843AD2AF"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sap:business_application_software_integrated_solution:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CF38D1E1-E07F-4E51-AE76-E27E7CE4F55C",
"versionEndIncluding": "7.02",
"versionStartIncluding": "7.00"
},
{
"criteria": "cpe:2.3:a:sap:business_application_software_integrated_solution:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4CB61EF9-414F-4563-B091-3E9B708CAB1E",
"versionEndIncluding": "7.11",
"versionStartIncluding": "7.10"
},
{
"criteria": "cpe:2.3:a:sap:business_application_software_integrated_solution:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D90BE6E0-559E-4509-95EA-CB820611E16D",
"versionEndIncluding": "7.52",
"versionStartIncluding": "7.50"
},
{
"criteria": "cpe:2.3:a:sap:business_application_software_integrated_solution:7.30:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "990D5985-7828-4D8C-9463-CA077AB3881E"
},
{
"criteria": "cpe:2.3:a:sap:business_application_software_integrated_solution:7.31:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "341C07C1-2B4A-475D-B200-1021EB6B1F79"
},
{
"criteria": "cpe:2.3:a:sap:business_application_software_integrated_solution:7.40:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D80CC30-EE05-439F-BF2C-1267837137DE"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cna@sap.com"
}