First published: Wed Dec 09 2020(Updated: )
SAP Disclosure Management, version - 10.1, provides capabilities for authorized users to upload and download content of specific file type. In some file types it is possible to enter formulas which can call external applications or execute scripts. The execution of a payload (script) on target machine could be used to steal and modify the data available in the spreadsheet
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Disclosure Management | =10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-26828.
The severity rating of CVE-2020-26828 is medium (6.4).
The affected software is SAP Disclosure Management version 10.1.
The vulnerability can be exploited by uploading and downloading content of specific file types that allow the execution of external applications or scripts.
Yes, SAP has released patches and fixes for CVE-2020-26828. It is recommended to update to the latest version of SAP Disclosure Management.