CVE-2018-2368: SAP NetWeaver System Landscape Directory

Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.

SAP NetWeaver System Landscape Directory, LM-CORE 7.10, 7.20, 7.30, 7.31, 7.40, does not perform any authentication checks for functionalities that require user identity.

Affected products

  • SAP NetWeaver System Landscape Directory: version 7.10 only; version 7.20 only; version 7.30 only; version 7.31 only; version 7.40 only

Published 2018-03-01. Last modified 2026-06-17.