CVE-2018-2487: SAP Disclosure Management
High severity, CVSS 8.3. EPSS: 1.5% chance of exploitation in the next 30 days.
SAP Disclosure Management 10.x allows an attacker to exploit through a specially crafted zip file provided by users: When extracted in specific use cases, files within this zip file can land in different locations than the originally intended extraction point.
Affected products
- SAP Disclosure Management: version 10.1 only
Published 2018-11-13. Last modified 2026-06-17.