CVE-2018-2380: SAP Customer Relationship Management (CRM) Path Traversal Vulnerability
Medium severity, CVSS 6.6. Actively exploited: in CISA KEV since 2021-11-03. EPSS: 28.9% chance of exploitation in the next 30 days.
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
Affected products
- SAP Customer Relationship Management: version 7.01 only; version 7.02 only; version 7.30 only; version 7.31 only; version 7.33 only; version 7.54 only
Published 2018-03-01. Last modified 2026-06-17.