7.8
CVE-2018-2488
- EPSS 0.19%
- Veröffentlicht 13.11.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 04:03:54
- Quelle cna@sap.com
- CVE-Watchlists
- Unerledigt
It is possible for a malware application installed on an Android device to send local push notifications with an empty message to SAP Fiori Client and cause the application to crash. SAP Fiori Client version 1.11.5 in Google Play store addresses these issues and users must update to that version.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Fiori Client Version < 1.11.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.376 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.8 | 1.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|