CVE-2018-2504: SAP NetWeaver Application Server Java
Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.
SAP NetWeaver AS Java Web Container service does not validate against whitelist the HTTP host header which can result in HTTP Host Header Manipulation or Cross-Site Scripting (XSS) vulnerability. This is fixed in versions 7.10, 7.11, 7.20, 7.30, 7.31, 7.40, 7.50.
Affected products
- SAP NetWeaver Application Server Java: version 7.10 only; version 7.11 only; version 7.20 only; version 7.30 only; version 7.31 only; version 7.40 only; …
Published 2018-12-11. Last modified 2026-06-17.