CVE-2018-2366: Redwood SAP Business Process Automation

Medium severity, CVSS 4.3. EPSS: 1.5% chance of exploitation in the next 30 days.

SAP Business Process Automation (BPA) By Redwood, 9.0, 9.1, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs.

Affected products

  • Redwood SAP Business Process Automation: version 9.0 only; version 9.1 only

Published 2018-03-14. Last modified 2026-06-17.