VulnerabilityModified
CVE-2018-2418
SAP MaxDB ODBC driver (all versions before 7.9.09.07) allows an attacker to inject code that can be executed by the application.
CRITICAL 9.8EPSS 1.83%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.83%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
SAP MaxDB ODBC driver (all versions before 7.9.09.07) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.83% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- sap/maxdb odbc driver
- Source
- cna@sap.com
References
- http://www.securityfocus.com/bid/104115Third Party Advisory, VDB Entry
- https://blogs.sap.com/2018/05/08/sap-security-patch-day-may-2018/Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2610231Permissions Required, Vendor Advisory
- http://www.securityfocus.com/bid/104115Third Party Advisory, VDB Entry
- https://blogs.sap.com/2018/05/08/sap-security-patch-day-may-2018/Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2610231Permissions Required, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.