CVE-2018-2460: SAP Business One

Medium severity, CVSS 5.9. EPSS: 0.8% chance of exploitation in the next 30 days.

SAP Business One Android application, version 1.2, does not verify the certificate properly for HTTPS connection. This allows attacker to do MITM attack.

Affected products

  • SAP Business One: version 1.2 only

Published 2018-09-11. Last modified 2026-06-17.