First published: Tue Nov 13 2018(Updated: )
SAP Disclosure Management 10.x allows an attacker to exploit through a specially crafted zip file provided by users: When extracted in specific use cases, files within this zip file can land in different locations than the originally intended extraction point.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Disclosure Management | =10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-2487 is high with a severity value of 8.3.
SAP Disclosure Management 10.x is affected by CVE-2018-2487.
An attacker can exploit CVE-2018-2487 by providing a specially crafted zip file to the system, which can result in files being extracted to unintended locations.
To fix CVE-2018-2487, it is recommended to apply the necessary patches or updates provided by SAP.
You can find more information about CVE-2018-2487 on the following references: [SecurityFocus](http://www.securityfocus.com/bid/105908), [SAP Note 2701410](https://launchpad.support.sap.com/#/notes/2701410), and [SAP Community Wiki](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=503809832).