« Volver al listado

CVE-2018-2433

Estado: ModificadaAlta (7.5)—

SAP Gateway (SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21EXT, 7.22 and 7.22EXT; SAP KERNEL 7.21, 7.22, 7.45, 7.49 and 7.53) allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-2433",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cna@sap.com",
      "affectedData": [
        {
          "vendor": "SAP",
          "product": "SAP Gateway",
          "versions": [
            {
              "status": "affected",
              "version": "SAP KERNEL 32 NUC 7.21, 7.21EXT, 7.22 and 7.22EXT"
            },
            {
              "status": "affected",
              "version": "SAP KERNEL 32 Unicode 7.21, 7.21EXT, 7.22 and 7.22EXT"
            },
            {
              "status": "affected",
              "version": "SAP KERNEL 64 NUC 7.21, 7.21EXT, 7.22 and 7.22EXT"
            },
            {
              "status": "affected",
              "version": "SAP KERNEL 64 Unicode 7.21, 7.21EXT, 7.22 and 7.22EXT"
            },
            {
              "status": "affected",
              "version": "SAP KERNEL  7.21, 7.22, 7.45, 7.49 and 7.53"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-07-10T18:29:00.907",
  "references": [
    {
      "url": "https://launchpad.support.sap.com/#/notes/2597913",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=497256000",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://launchpad.support.sap.com/#/notes/2597913",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=497256000",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "SAP Gateway (SAP KERNEL 32 NUC, SAP KERNEL 32 Unicode, SAP KERNEL 64 NUC, SAP KERNEL 64 Unicode 7.21, 7.21EXT, 7.22 and 7.22EXT; SAP KERNEL 7.21, 7.22, 7.45, 7.49 and 7.53) allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service."
    },
    {
      "lang": "es",
      "value": "SAP Gateway (SAP KERNEL 32 NUC; SAP KERNEL 32 Unicode; SAP KERNEL 64 NUC; SAP KERNEL 64 Unicode 7.21, 7.21EXT, 7.22 y 7.22EXT y SAP KERNEL 7.21, 7.22, 7.45, 7.49 y 7.53) permite que un atacante evite que usuarios legítimos accedan a un servicio, ya sea inundándolo o provocando su cierre inesperado."
    }
  ],
  "lastModified": "2026-06-17T01:55:41.393",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:sap_kernel:7.21:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B1DB2B37-EC52-4FE6-9861-A98A9E365B61"
            },
            {
              "criteria": "cpe:2.3:a:sap:sap_kernel:7.21ext:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "168D38D8-CE37-4FF4-B089-DCBB0D5A3387"
            },
            {
              "criteria": "cpe:2.3:a:sap:sap_kernel:7.22:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "80D1ECE8-0465-4B82-A0B7-BC55438FFC43"
            },
            {
              "criteria": "cpe:2.3:a:sap:sap_kernel:7.22ext:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "56247321-E033-4097-A176-BE71DEBD5920"
            },
            {
              "criteria": "cpe:2.3:a:sap:sap_kernel:7.45:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "517E04CB-B712-477E-8F64-B35F9D0D932B"
            },
            {
              "criteria": "cpe:2.3:a:sap:sap_kernel:7.49:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "018F8061-43B6-4F29-B914-C779569C58CD"
            },
            {
              "criteria": "cpe:2.3:o:sap:sap_kernel:7.53:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "306EBEDB-BF90-46C5-99B1-C7ADAF1B8611"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cna@sap.com"
}