CVE-2018-2428: SAP Infrastructure
Medium severity, CVSS 5.3. EPSS: 1.7% chance of exploitation in the next 30 days.
Under certain conditions SAP UI5 Handler allows an attacker to access information which would otherwise be restricted. Software components affected are: SAP Infrastructure 1.0, SAP UI 7.4, 7.5, 7.51, 7.52 and version 2.0 of SAP UI for SAP NetWeaver 7.00.
Affected products
- SAP Infrastructure: version 1.0 only
- SAP UI: version 2.0 only; version 7.4 only; version 7.5 only; version 7.51 only; version 7.52 only
Published 2018-06-12. Last modified 2026-06-17.