CVE-2020-6290: Medium severity sap disclosure management vulnerability
Published Jul 14, 2020
·Updated
SAP Disclosure Management, version 10.1, is vulnerable to Session Fixation attacks wherein the attacker tricks the user into using a specific session ID.
Affected Software
1 affected component
SAP Disclosure Management=10.1
Event History
Jul 14, 2020
CVE Published
via MITRE·12:30 PM
Data Sourced
via MITRE·12:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2020-6290?
CVE-2020-6290 is a vulnerability in SAP Disclosure Management version 10.1.
2
How does CVE-2020-6290 affect SAP Disclosure Management?
CVE-2020-6290 allows for Session Fixation attacks in SAP Disclosure Management version 10.1.
3
What is a Session Fixation attack?
A Session Fixation attack is when an attacker tricks a user into using a specific session ID.
4
How severe is CVE-2020-6290?
CVE-2020-6290 has a severity score of 6.3, which is considered medium.
5
How can I fix CVE-2020-6290?
To fix CVE-2020-6290, you should update to a non-vulnerable version of SAP Disclosure Management.