CVE detail
CVE-2018-2361
In SAP Solution Manager 7.20, the role SAP_BPO_CONFIG gives the Business Process Operations (BPO) configuration user more authorization than required for configuring the BPO tools.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 6.9 · diversity 5.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
1 source links · newest first
- SAP Publishes Light Patch Day for January 2018SecurityWeek
SAP this week released its monthly set of security patches to address just three vulnerabilities in its products, all three rated Medium severity.
newswww.securityweek.comJan 10, 2018, 3:53 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-72886CVSS 9.9 · Critical
Dokploy is a free, self-hostable Platform as a Service (PaaS). From 0.29.2 until 0.29.13, schedule.create and schedule.update in apps/dokploy/server/api/routers/schedule.ts derive…
- CVE-2026-69118CVSS 8.7 · High
Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execute arbitrary PHP code. Attacker…
- CVE-2026-12624CVSS 4.3 · Medium
Vault’s ACL policy engine did not consistently enforce a wildcard (glob) deny rule against LIST requests made with a trailing slash on the denied path. This may allow a token hold…
- CVE-2026-21077CVSS 6.9 · Medium
Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
- CVE-2026-21076CVSS 6.9 · Medium
Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
- CVE-2026-19350CVSS 5.3 · Medium
A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulatio…