CVE-2018-2486: SAP Marketing Sapscore

Medium severity, CVSS 5.4. EPSS: 1% chance of exploitation in the next 30 days.

SAP Marketing (UICUAN (1.20, 1.30, 1.40), SAPSCORE (1.13, 1.14)) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

Affected products

  • SAP Marketing Sapscore: version 1.13 only; version 1.14 only
  • SAP Marketing Uicuan: version 1.20 only; version 1.30 only; version 1.40 only

Published 2018-12-11. Last modified 2026-06-17.