First published: Tue Apr 10 2018(Updated: )
SAP Disclosure Management 10.1 allows an attacker to upload any file without proper file format validation.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Disclosure Management | =10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-2404 is critical, with a severity score of 9.8.
The affected software is SAP Disclosure Management 10.1.
CVE-2018-2404 allows an attacker to upload any file without proper file format validation in SAP Disclosure Management 10.1.
Yes, a security patch is available for CVE-2018-2404. Please refer to the SAP Security Patch Day April 2018 for more information.
You can find more information about CVE-2018-2404 on the following links: [SecurityFocus](http://www.securityfocus.com/bid/103727), [SAP Blogs](https://blogs.sap.com/2018/04/10/sap-security-patch-day-april-2018/), [SAP Support Notes](https://launchpad.support.sap.com/#/notes/2607052).