CVE-2018-2448: SAP Supplier Relationship Management Mdm Catalog

Medium severity, CVSS 5.3. EPSS: 1.4% chance of exploitation in the next 30 days.

Under certain conditions SAP SRM-MDM (CATALOG versions 3.0, 7.01, 7.02) utilities functionality allows an attacker to access information of user existence which would otherwise be restricted.

Affected products

  • SAP Supplier Relationship Management Mdm Catalog: version 3.0 only; version 7.01 only; version 7.02 only

Published 2018-08-14. Last modified 2026-06-17.