Vulnerabilities > CVE-2018-2487 - Unspecified vulnerability in SAP Disclosure Management 10.1

047910
CVSS 8.3 - HIGH
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
high complexity
sap

Summary

SAP Disclosure Management 10.x allows an attacker to exploit through a specially crafted zip file provided by users: When extracted in specific use cases, files within this zip file can land in different locations than the originally intended extraction point.

Vulnerable Configurations

Part Description Count
Application
Sap
1