CVE-2018-2440: SAP Dynamic Authorization Management

Medium severity, CVSS 4.4. EPSS: 0.3% chance of exploitation in the next 30 days.

Under certain circumstances SAP Dynamic Authorization Management (DAM) by NextLabs (Java Policy Controller versions 7.7 and 8.5) exposes sensitive information in the application logs.

Affected products

  • SAP Dynamic Authorization Management: version 7.7 only; version 8.5 only

Published 2018-07-10. Last modified 2026-06-17.