CVE-2018-2424: SAP Hana Database

High severity, CVSS 7.5. EPSS: 2.4% chance of exploitation in the next 30 days.

SAP UI5 did not validate user input before adding it to the DOM structure. This may lead to malicious user-provided JavaScript code being added to the DOM that could steal user information. Software components affected are: SAP Hana Database 1.00, 2.00; SAP UI5 1.00; SAP UI5 (Java) 7.30, 7.31, 7.40, 7,50; SAP UI 7.40, 7.50, 7.51, 7.52, and version 2.0 of SAP UI for SAP NetWeaver 7.00

Affected products

  • SAP Hana Database: version 1.00 only; version 2.00 only
  • SAP UI: version 2.0 only; version 7.40 only; version 7.50 only; version 7.51 only; version 7.52 only
  • SAP UI5: version 1.00 only
  • SAP UI5 Java: version 7.30 only; version 7.31 only; version 7.40 only; version 7.50 only

Published 2018-06-12. Last modified 2026-06-17.