ZeroHour

CVE-2020-6292

CVSS 3.1
8.8 high
EPSS
<1%p46
Published
()
Modified
Description

Logout mechanism in SAP Disclosure Management, version 10.1, does not invalidate one of the session cookies, leading to Insufficient Session Expiration.

Vendors
sap
Products
disclosure management
Weakness
CWE-613
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.