PT-2020-19080 · Sap · Sap Disclosure Management

Published

2020-07-14

·

Updated

2020-07-14

·

CVE-2020-6290

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SAP Disclosure Management version 10.1
Description The issue allows an attacker to perform Session Fixation attacks by tricking the user into using a specific session ID.
Recommendations For SAP Disclosure Management version 10.1, update to a version that includes a fix for this issue to prevent Session Fixation attacks.

Fix

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6290

Affected Products

Sap Disclosure Management