VendorsSAPsupplier_relationship_management_mdm_catalogall versions
Vulnerabilities

SAP Supplier Relationship Management MDM Catalog

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2018-2449
SAP SRM MDM Catalog versions 3.73, 7.31, 7.32 in (SAP NetWeaver 7.3) - import functionality does not perform authentication checks for valid repository user. This is an unauthenticated functionality that you can use on windows machines to do SMB relaying.
Published 2018-08-14 · Modified
8.6EPSS 0.016
CVE-2018-2448
Under certain conditions SAP SRM-MDM (CATALOG versions 3.0, 7.01, 7.02) utilities functionality allows an attacker to access information of user existence which would otherwise be restricted.
Published 2018-08-14 · Modified
5.3EPSS 0.014