CVE Vulnerabilities

CVE-2018-2487

Published: Nov 13, 2018 | Modified: Aug 24, 2020
CVSS 3.x
8.3
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

SAP Disclosure Management 10.x allows an attacker to exploit through a specially crafted zip file provided by users: When extracted in specific use cases, files within this zip file can land in different locations than the originally intended extraction point.

Affected Software

Name Vendor Start Version End Version
Disclosure_management Sap 10.1 (including) 10.1 (including)

References