CVE-2018-2449: SAP Supplier Relationship Management Mdm Catalog

High severity, CVSS 8.6. EPSS: 1.6% chance of exploitation in the next 30 days.

SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid repository user. This is an unauthenticated functionality that you can use on windows machines to do SMB relaying.

Affected products

  • SAP Supplier Relationship Management Mdm Catalog: version 3.73 only; version 7.31 only; version 7.32 only

Published 2018-08-14. Last modified 2026-06-17.