CVE-2018-2459
No sign of exploitation. No public exploitation artifact known so far.
A flaw in SAP Mobile Platform 3.0's Offline OData feature allows users to occasionally receive data belonging to other users when using delta tokens (a feature enabled by default). This is a privacy breach that exposes sensitive information to unauthorized users.
The Offline OData delta token mechanism in SAP Mobile Platform 3.0 fails to properly isolate user data during synchronization operations. An authenticated user with legitimate access to the application may receive data records assigned to other users due to improper token handling or cache isolation. The vulnerability affects deployments using the default delta token configuration and impacts data confidentiality.