PT-2018-15564 · Nextlabs · Sap Dynamic Authorization Management

Published

2018-07-10

·

Updated

2018-09-06

·

CVE-2018-2440

CVSS v3.1

4.4

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP Dynamic Authorization Management (DAM) by NextLabs versions 7.7 through 8.5
Description The issue exposes sensitive information in the application logs under certain circumstances.
Recommendations For versions 7.7 through 8.5, consider restricting access to the application logs to minimize the risk of sensitive information exposure until a patch is available.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-2440

Affected Products

Sap Dynamic Authorization Management