Loading
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
Use CWE-22, Sap vendor hub and Customer Relationship Management product page to widen CVE-2018-2380 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2014-8669, CVE-2013-7095 and CVE-2017-15296 for nearby disclosures in the same product family. Additional editorial context is available in The Weekly Cybersecurity Brief: February 13th, 2026.