CVE-2018-2403: SAP Disclosure Management
Medium severity, CVSS 6.5. EPSS: 1.1% chance of exploitation in the next 30 days.
Under certain conditions, SAP Disclosure Management 10.1 allows an attacker to access information which would otherwise be restricted. It is possible for an authorized user to get SAP Disclosure Management to point a specific chapter type to a chapter the user has not been given access to.
Affected products
- SAP Disclosure Management: version 10.1 only
Published 2018-04-10. Last modified 2026-06-17.