PT-2020-19081 · Sap · Sap Disclosure Management

Published

2020-07-14

·

Updated

2020-07-14

·

CVE-2020-6291

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP Disclosure Management version 10.1
Description The session mechanism in SAP Disclosure Management does not have expiration data set, allowing unlimited access after authenticating once. This leads to insufficient session expiration, potentially allowing unauthorized access.
Recommendations For SAP Disclosure Management version 10.1, consider implementing a session expiration mechanism to limit the duration of access after a user authenticates. As a temporary workaround, restrict access to sensitive areas of the application to minimize the risk of exploitation.

Fix

Insufficient Session Expiration

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-6291

Affected Products

Sap Disclosure Management