AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-2491

HIGH · CVSS 7.8 EPSS 0.79%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-11-13 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2018-2491
Severity
HIGH
CVSS
7.8
EPSS
0.79%
Java

Original NVD Description

When opening a deep link URL in SAP Fiori Client with log level set to "Debug", the client application logs the URL to the log file. If this URL contains malicious JavaScript code it can eventually run inside the built-in log viewer of the application in case user opens the viewer and taps on the hyperlink in the viewer. SAP Fiori Client version 1.11.5 in Google Play store addresses these issues and users must update to that version.