CVE-2018-2367: SAP Business Application Software Integrated Solution

High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.

ABAP File Interface in, SAP BASIS, from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.

Affected products

  • SAP Business Application Software Integrated Solution: from 7.00, up to and including 7.02; from 7.10, up to and including 7.11; from 7.50, up to and including 7.52; version 7.30 only; version 7.31 only; version 7.40 only

Published 2018-03-01. Last modified 2026-06-17.