CVE-2018-2470: SAP NetWeaver

Medium severity, CVSS 6.1. EPSS: 1.3% chance of exploitation in the next 30 days.

In SAP NetWeaver Application Server for ABAP, from 7.0 to 7.02, 7.30, 7.31, 7.40 and from 7.50 to 7.53, applications do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

Affected products

  • SAP NetWeaver: from 7.0, up to and including 7.02; from 7.50, up to and including 7.53; version 7.30 only; version 7.31 only; version 7.40 only

Published 2018-10-09. Last modified 2026-06-17.