ZeroHour

CVE-2020-6291

CVSS 3.1
8.8 high
EPSS
<1%p48
Published
()
Modified
Description

SAP Disclosure Management, version 10.1, session mechanism does not have expiration data set therefore allows unlimited access after authenticating once, leading to Insufficient Session Expiration

Vendors
sap
Products
disclosure management
Weakness
CWE-613
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.