CVE-2020-6291

HIGH

SAP Disclosure Mgmt <10.1 - Insufficient Session Expiration

Title source: llm
STIX 2.1

Description

SAP Disclosure Management, version 10.1, session mechanism does not have expiration data set therefore allows unlimited access after authenticating once, leading to Insufficient Session Expiration

References (2)

Core 2
Core References
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/2758000

Scores

CVSS v3 8.8
EPSS 0.0015
EPSS Percentile 35.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-613
Status published
Products (1)
sap/disclosure_management 10.1
Published Jul 14, 2020
Tracked Since Feb 18, 2026