CVE-2018-2403
Last modified
CVE-2018-2403 is a vulnerability of currently unknown severity. Under certain conditions, SAP Disclosure Management 10.1 allows an attacker to access information which would otherwise be restricted. It is possible for an authorized user to get SAP Disclosure Management to point a specific chapter type to a chapter the user has not been given access to.. EPSS estimates a 1.20% chance of exploitation in the next 30 days.
Description
Under certain conditions, SAP Disclosure Management 10.1 allows an attacker to access information which would otherwise be restricted. It is possible for an authorized user to get SAP Disclosure Management to point a specific chapter type to a chapter the user has not been given access to.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Disclosure Management | 10.1 |
References
- http://www.securityfocus.com/bid/103727Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2595800Permissions Required
- http://www.securityfocus.com/bid/103727Third Party Advisory, VDB Entry
- https://launchpad.support.sap.com/#/notes/2595800Permissions Required
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-2403?
How severe is CVE-2018-2403?
How do I fix CVE-2018-2403?
Are you affected by CVE-2018-2403?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
