« Volver al listado

CVE-2018-2415

Estado: ModificadaMedia (4.7)—

SAP NetWeaver Application Server Java Web Container and HTTP Service (Engine API, from 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; J2EE Engine Server Core 7.11, 7.30, 7.31, 7.40, 7.50) do not sufficiently encode user controlled inputs, resulting in a content spoofing vulnerability when error pages are displayed.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-2415",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "cna@sap.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 4.7,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 4.7,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cna@sap.com",
      "affectedData": [
        {
          "vendor": "SAP SE",
          "product": "SAP NetWeaver Application Server (Engine API)",
          "versions": [
            {
              "status": "affected",
              "version": "from 7.10 to 7.11"
            },
            {
              "status": "affected",
              "version": "7.30"
            },
            {
              "status": "affected",
              "version": "7.31"
            },
            {
              "status": "affected",
              "version": "7.40"
            },
            {
              "status": "affected",
              "version": "7.50"
            }
          ]
        },
        {
          "vendor": "SAP SE",
          "product": "SAP NetWeaver Application Server (J2EE Engine Server Core)",
          "versions": [
            {
              "status": "affected",
              "version": "7.11"
            },
            {
              "status": "affected",
              "version": "7.30"
            },
            {
              "status": "affected",
              "version": "7.31"
            },
            {
              "status": "affected",
              "version": "7.40"
            },
            {
              "status": "affected",
              "version": "7.50"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-05-09T20:29:00.667",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/104130",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://blogs.sap.com/2018/05/08/sap-security-patch-day-may-2018/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://launchpad.support.sap.com/#/notes/2550202",
      "tags": [
        "Permissions Required"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/104130",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://blogs.sap.com/2018/05/08/sap-security-patch-day-may-2018/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://launchpad.support.sap.com/#/notes/2550202",
      "tags": [
        "Permissions Required"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-172"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "SAP NetWeaver Application Server Java Web Container and HTTP Service (Engine API, from 7.10 to 7.11, 7.30, 7.31, 7.40, 7.50; J2EE Engine Server Core 7.11, 7.30, 7.31, 7.40, 7.50) do not sufficiently encode user controlled inputs, resulting in a content spoofing vulnerability when error pages are displayed."
    },
    {
      "lang": "es",
      "value": "Java Web Container y HTTP Service en SAP NetWeaver Application Server (Engine API, de la versión 7.10 a la 7.11, 7.30, 7.31, 7.40, 7.50; J2EE Engine Server Core 7.11, 7.30, 7.31, 7.40 y 7.50) no cifran lo suficiente entradas controladas por el usuario, lo que resulta en una vulnerabilidad de suplantación de contenido cuando se muestran páginas de error."
    }
  ],
  "lastModified": "2026-06-17T01:55:39.703",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:netweaver_java_web_container_and_http_service_engine:7.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3E0BC4DE-4775-47A9-994A-50D7988C985C"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_java_web_container_and_http_service_engine:7.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D7167F0B-0C1C-4624-A4D5-0133EFCB142E"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_java_web_container_and_http_service_engine:7.30:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4E7BC134-E387-43D8-B05F-20EA90E4D95A"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_java_web_container_and_http_service_engine:7.31:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8B8D9985-73BA-47BE-855E-EC5C00E4B1FC"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_java_web_container_and_http_service_engine:7.40:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1EA345DD-9D93-496C-9B0C-31A37D4D900F"
            },
            {
              "criteria": "cpe:2.3:a:sap:netweaver_java_web_container_and_http_service_engine:7.50:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "48B78E42-FC8D-4C4B-94CD-8D083406DF72"
            }
          ],
          "operator": "OR"
        }
      ]
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:j2ee_engine_server_core:7.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "36870366-7DA1-45F5-82EA-024FBF025CFA"
            },
            {
              "criteria": "cpe:2.3:a:sap:j2ee_engine_server_core:7.30:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A8C1EAF6-BB67-44B3-A6E3-5DB8EE114236"
            },
            {
              "criteria": "cpe:2.3:a:sap:j2ee_engine_server_core:7.31:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7A334645-13ED-4D2A-A802-7DE6B0C013C3"
            },
            {
              "criteria": "cpe:2.3:a:sap:j2ee_engine_server_core:7.40:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8C374A22-DA62-42E4-A8D9-646DBD575770"
            },
            {
              "criteria": "cpe:2.3:a:sap:j2ee_engine_server_core:7.50:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "435F8143-1187-4D2C-975E-EC96E580D0B6"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cna@sap.com"
}