First published: Tue Apr 10 2018(Updated: )
Under certain conditions, SAP Disclosure Management 10.1 allows an attacker to access information which would otherwise be restricted. It is possible for an authorized user to get SAP Disclosure Management to point a specific chapter type to a chapter the user has not been given access to.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Disclosure Management | =10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this SAP Disclosure Management vulnerability is CVE-2018-2403.
The severity rating for CVE-2018-2403 is medium with a value of 6.5.
Under certain conditions, an attacker can exploit CVE-2018-2403 by accessing information that is otherwise restricted.
The affected software for CVE-2018-2403 is SAP Disclosure Management 10.1.
Yes, there are references available for CVE-2018-2403. You can find them at the following links: [http://www.securityfocus.com/bid/103727](http://www.securityfocus.com/bid/103727), [https://blogs.sap.com/2018/04/10/sap-security-patch-day-april-2018/](https://blogs.sap.com/2018/04/10/sap-security-patch-day-april-2018/), [https://launchpad.support.sap.com/#/notes/2595800](https://launchpad.support.sap.com/#/notes/2595800).