CVE-2018-2474

Severity CVSS v4.0:
Pending analysis
Type:
CWE-352 Cross-Site Request Forgery (CSRF)
Publication date:
09/10/2018
Last modified:
04/01/2019

Description

SAP Fiori 1.0 for SAP ERP HCM (Approve Leave Request, version 2) application allows an attacker to trick an authenticated user to send unintended request to the web server. This vulnerability is due to insufficient CSRF protection.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:fiori:1.0:*:*:*:*:erp_hcm:*:*