CVE-2018-2435: SAP NetWeaver Enterprise Portal
Medium severity, CVSS 6.1. EPSS: 1.3% chance of exploitation in the next 30 days.
SAP NetWeaver Enterprise Portal from 7.0 to 7.02, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not sufficiently encode user controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.
Affected products
- SAP NetWeaver Enterprise Portal: from 7.0, up to and including 7.02; version 7.11 only; version 7.20 only; version 7.30 only; version 7.31 only; version 7.40 only; …
Published 2018-07-10. Last modified 2026-06-17.