CVE-2018-2416
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 1.5%
exploitation probability
1.5%top 28% of all CVEs
observed exploitation
nono source reports it
SAP Identity Management 7.2 and 8.0 do not sufficiently validate an XML document accepted from an untrusted source.
Affected products
SAP · SAP Identity ManagementReferences
https://blogs.sap.com/2018/05/08/sap-security-patch-day-may-2018/https://launchpad.support.sap.com/#/notes/2597875https://launchpad.support.sap.com/#/notes/2653519https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=499352742http://www.securityfocus.com/bid/104106http://www.securityfocus.com/bid/105076