LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-2380: SAP Customer Relationship Management (CRM) Path Traversal Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-2380 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

SAP Customer Relationship Management (CRM) contains a path traversal vulnerability that allows an attacker to exploit insufficient validation of path information provided by users.

CVE-2018-2380 is a path traversal weakness in SAP Customer Relationship Management (CRM). Insufficient validation of user-supplied path information can let an attacker reach files or locations outside the intended scope. CISA notes known ransomware use of this vulnerability, so unpatched CRM instances that handle customer and business data deserve prompt attention.

Defenders should treat this as a high-priority inventory and patching task. Confirm exact affected components, versions, and fixes only against the vendor advisory; do not rely on secondary summaries alone.

How it works

This issue is classed as CWE-22 (path traversal). In products of this type, the application accepts path or filename input from a user or client and uses it when accessing the filesystem or related resources. When that input is not fully canonicalized and constrained to an allowed base directory, an attacker can craft sequences (for example, directory-ascent patterns) that cause the application to resolve a path outside the intended area.

Abuse typically means sending specially formed requests that supply malicious path information to a vulnerable CRM interface or service. Successful exploitation can lead to unauthorized read or write of files the CRM process can access, depending on how the product uses the path and on the privileges of the service account. Exact request format, parameters, and impact vary by component; treat any public proof-of-concept as untrusted and validate behavior only in a controlled lab against vendor documentation.

Am I affected? How to find it in your systems

SAP CRM is commonly deployed in enterprise environments that manage customer data, sales, and service processes—on-premises or in hosted landscapes that still run the CRM application stack. Inventory every system that runs SAP CRM or related CRM application servers, including non-production and integration hosts that may be reachable from less-trusted networks.

How to remediate

Patch first. Apply the updates SAP provides for this vulnerability exactly as described in the vendor advisory and in line with CISA’s required action to apply updates per vendor instructions. Use your normal SAP transport and change-management process so that dependent systems stay consistent.

If you can't patch immediately

Until the vendor update is installed, reduce likelihood and impact with compensating controls.

If your data may have been exposed

Vulnerabilities with known ransomware use are frequently chained into broader intrusion and data theft. If CRM systems were unpatched and reachable during a relevant window, assume possible unauthorized access to data the application could read, investigate with your IR process, and follow legal and regulatory notification duties where they apply. You can run a free exposure scan of your email addresses against known breach data as one quick check for credentials or identities that may already appear in public breach sets, then prioritize password resets and monitoring for those accounts.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedSAP · Customer Relationship Management (CRM)
WeaknessCWE-22
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities