CVE-2018-2487: SAP Disclosure Management

High severity, CVSS 8.3. EPSS: 1.5% chance of exploitation in the next 30 days.

SAP Disclosure Management 10.x allows an attacker to exploit through a specially crafted zip file provided by users: When extracted in specific use cases, files within this zip file can land in different locations than the originally intended extraction point.

Affected products

  • SAP Disclosure Management: version 10.1 only

Published 2018-11-13. Last modified 2026-06-17.