CVE-2018-2436: SAP r/3 Enterprise Retail

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

Executing transaction WRCK in SAP R/3 Enterprise Retail (EHP6) does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges.

Affected products

  • SAP r/3 Enterprise Retail: affected versions not specified

Published 2018-07-10. Last modified 2026-06-17.