Disclosure Management
Vendor:
First CVE: Apr 10, 2018 · Active for 8 years
16
Total CVEs
More Total CVEs than 93% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
7.5
Avg CVSS
Higher Avg CVSS than 62% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Disclosure Management over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 10, 2018
8 years ago
Most Recent CVE
Dec 13, 2022
1,322 days ago
CVE Severity & Scoring
Disclosure Management16 CVEs
44%
50%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network16 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (87.5%)
High2 (12.5%)
Unknown0 (0.0%)
User Interaction
None10 (62.5%)
Unknown0 (0.0%)
Required6 (37.5%)
Privileges Required
Low11 (68.8%)
High0 (0.0%)
None5 (31.3%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-2404CRITICAL SAP Disclosure Management 10.1 allows an attacker to upload any file without proper file format validation. | Apr 10, 2018 | 9.8 | 29 | NO | NO |
CVE-2020-6292HIGH Logout mechanism in SAP Disclosure Management, version 10.1, does not invalidate one of the session cookies, leading to Insufficient Session Expiration. | Jul 14, 2020 | 8.8 | 27 | NO | NO |
CVE-2019-0258HIGH SAP Disclosure Management, version 10.01, does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. | Feb 15, 2019 | 8.8 | 27 | NO | NO |
CVE-2018-2412HIGH SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. | Apr 10, 2018 | 8.8 | 27 | NO | NO |
CVE-2020-6291HIGH SAP Disclosure Management, version 10.1, session mechanism does not have expiration data set therefore allows unlimited access after authenticating once, leading to Insufficient Se | Jul 14, 2020 | 8.8 | 26 | NO | NO |
CVE-2018-2487HIGH SAP Disclosure Management 10.x allows an attacker to exploit through a specially crafted zip file provided by users: When extracted in specific use cases, files within this zip fil | Nov 13, 2018 | 8.3 | 26 | NO | NO |
CVE-2018-2413HIGH SAP Disclosure Management 10.1 does not perform necessary authorization checks for an authenticated user, resulting in escalation of privileges. | Apr 10, 2018 | 8.8 | 26 | NO | NO |
CVE-2022-41274MEDIUM SAP Disclosure Management - version 10.1, allows an authenticated attacker to exploit certain misconfigured application endpoints to read sensitive data. These endpoints are normal | Dec 13, 2022 | 6.5 | 22 | NO | NO |
CVE-2020-6290MEDIUM SAP Disclosure Management, version 10.1, is vulnerable to Session Fixation attacks wherein the attacker tricks the user into using a specific session ID. | Jul 14, 2020 | 6.3 | 22 | NO | NO |
CVE-2020-6289HIGH SAP Disclosure Management, version 10.1, had insufficient protection against Cross-Site Request Forgery, which could be used to trick user in to browsing malicious site. | Jul 14, 2020 | 8.8 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Disclosure Management
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 10.1 | 13 | 7.8 | 1.0% | 0 | 0 |
| 10.01 | 1 | 8.8 | 1.4% | 0 | 0 |