CVE-2018-2403
CVE-2018-2403
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.4EPSS 1.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
10 Apr 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Under certain conditions, SAP Disclosure Management 10.1 allows an attacker to access information which would otherwise be restricted. It is possible for an authorized user to get SAP Disclosure Management to point a specific chapter type to a chapter the user has not been given access to.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Affected products
SAP SE · SAP Disclosure ManagementWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →