← Vulnerability feed

Vulnerability record · CVE-2018-2380 · published 1 March 2018

CVE-2018-2380: SAP CRM path traversal in user-supplied path validation

Sap · Customer Relationship Management

SAP CRM versions 7.01, 7.02, 7.30, 7.31, 7.33 and 7.54 fail to properly validate user-supplied path information, allowing parent-directory traversal characters to reach file APIs. This lets an authenticated attacker read or write files outside the intended directory on the CRM server.

6.6 CVSS 3.1 Medium CISA KEV since 3 Nov 2021 Known ransomware use EPSS 29% · top 1.9% CWE-22 · Path traversal
6.6CVSS 3.1 base score, v2 6.5
29%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
11References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw is in CISA KEV with known ransomware use and public exploits, though exploitation requires high privileges and impact is limited to low confidentiality, integrity and availability.

What it is

SAP CRM versions 7.01, 7.02, 7.30, 7.31, 7.33 and 7.54 fail to properly validate user-supplied path information, allowing parent-directory traversal characters to reach file APIs. This lets an authenticated attacker read or write files outside the intended directory on the CRM server.

Impact

An attacker with access to the affected CRM functionality can traverse directories to access or manipulate files on the server, potentially exposing sensitive data or altering application files.

Attack surface

Reachable over the network through the CRM application's file-handling functionality; the CVSS vector indicates high privileges are required and no user interaction is needed.

Exploitation

Listed in CISA KEV since 2021-11-03 with known ransomware campaign use, and public exploit code exists (Exploit-DB 44292, GitHub erpscanteam/CVE-2018-2380); EPSS 30-day probability is about 0.29 (98th percentile).

What to do

  • Apply the SAP security patch referenced in SAP Security Patch Day February 2018 and SAP note 2547431.
  • Restrict network access to the CRM application and its file-handling endpoints to trusted users and networks.
  • Enforce least privilege on CRM accounts to limit which users can reach the vulnerable functionality.
  • Monitor and restrict file system permissions for the CRM service account to reduce traversal impact.

Detection

  • Review CRM and web server logs for path parameters containing '../' or encoded traversal sequences.
  • Alert on file access outside expected CRM directories by the CRM service account.
  • Hunt for requests matching known public exploit patterns for CVE-2018-2380.
  • Correlate unusual file reads or writes with CRM user sessions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-2380 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "SAP Customer Relationship Management (CRM) Path Traversal Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-2380 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2014-8669Sap customer relationship management code injection vulnerabilityThe SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code via unspecified vectors.EPSS 5.5%10.0CVE-2013-7095Sap customer relationship management vulnerabilityThe XML parser (crm_flex_data) in SAP Customer Relationship Management (CRM) 7.02 EHP 2 has unknown impact and attack vectors related to an XML Exter…EPSS 2.1%8.8CVE-2017-15296Sap customer relationship management cross-site request forgery vulnerabilityThe Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.EPSS 0.55%7.5CVE-2015-3980Sap customer relationship management sql injection vulnerabilitySQL injection vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary SQL commands via unspecifie…EPSS 1.4%7.5CVE-2015-3979Sap customer relationship management vulnerabilityUnspecified vulnerability in the Business Rules Framework (CRM-BF-BRF) in SAP CRM allows attackers to execute arbitrary code via unknown vectors, aka…EPSS 2.4%7.2CVE-2021-33676Sap customer relationship management missing authorization vulnerabilityA missing authority check in SAP CRM, versions - 700, 701, 702, 712, 713, 714, could be leveraged by an attacker with high privileges to compromise c…EPSS 0.91%6.3CVE-2023-27897Sap customer relationship management code injection vulnerabilityIn SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authoriz…EPSS 0.65%6.1CVE-2017-15294Sap customer relationship management cross-site scripting vulnerabilityThe Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.EPSS 0.98%

Source: NIST National Vulnerability Database (record CVE-2018-2380), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.