CVE-2018-2367: SAP Business Application Software Integrated Solution
High severity, CVSS 8.8. EPSS: 1.9% chance of exploitation in the next 30 days.
ABAP File Interface in, SAP BASIS, from 7.00 to 7.02, from 7.10 to 7.11, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
Affected products
- SAP Business Application Software Integrated Solution: from 7.00, up to and including 7.02; from 7.10, up to and including 7.11; from 7.50, up to and including 7.52; version 7.30 only; version 7.31 only; version 7.40 only
Published 2018-03-01. Last modified 2026-06-17.