CVE-2018-2403
published 2018-04-10CVE-2018-2403: Under certain conditions, SAP Disclosure Management 10.1 allows an attacker to access information which would otherwise be restricted. It is possible for an…
PriorityP433medium6.5CVSS 3.0
AVNACLPRLUINSUCHINAN
EPSS
1.20%
64.7th percentile
Under certain conditions, SAP Disclosure Management 10.1 allows an attacker to access information which would otherwise be restricted. It is possible for an authorized user to get SAP Disclosure Management to point a specific chapter type to a chapter the user has not been given access to.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | disclosure_management | — | — |
| sap_se | sap_disclosure_management | — | — |
| symfony | security | >= 2.8.0 < 2.8.37 | 2.8.37 |
| symfony | security | >= 3.0.0 < 3.3.17 | 3.3.17 |
| symfony | security | >= 3.4.0 < 3.4.7 | 3.4.7 |
| symfony | security | >= 4.0.0 < 4.0.7 | 4.0.7 |
| symfony | security-core | >= 2.8.0 < 2.8.37 | 2.8.37 |
| symfony | security-core | >= 3.0.0 < 3.3.17 | 3.3.17 |
| symfony | security-core | >= 3.4.0 < 3.4.7 | 3.4.7 |
| symfony | security-core | >= 4.0.0 < 4.0.7 | 4.0.7 |
| symfony | symfony | >= 2.8.0 < 2.8.37 | 2.8.37 |
| symfony | symfony | >= 3.0.0 < 3.3.17 | 3.3.17 |
| symfony | symfony | >= 3.4.0 < 3.4.7 | 3.4.7 |
| symfony | symfony | >= 4.0.0 < 4.0.7 | 4.0.7 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
ghsa9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Symfony Authentication Bypass
ghsa·2022-05-14·CVSS 9.8
CVE-2018-11407 [CRITICAL] CWE-287 Symfony Authentication Bypass
Symfony Authentication Bypass
An issue was discovered in the LDAP component in Symfony 2.8.x before 2.8.37, 3.3.x before 3.3.17, 3.4.x before 3.4.7, and 4.0.x before 4.0.7. It allows remote attackers to bypass authentication by logging in with a "null" password and valid username, which triggers an unauthenticated bind. **NOTE:** this issue exists because of an incomplete fix for CVE-2016-2403.
GHSA
GHSA-f456-7m27-wjmp: Under certain conditions, SAP Disclosure Management 10
ghsa_unreviewed·2022-05-13
CVE-2018-2403 [MEDIUM] GHSA-f456-7m27-wjmp: Under certain conditions, SAP Disclosure Management 10
Under certain conditions, SAP Disclosure Management 10.1 allows an attacker to access information which would otherwise be restricted. It is possible for an authorized user to get SAP Disclosure Management to point a specific chapter type to a chapter the user has not been given access to.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/103727https://blogs.sap.com/2018/04/10/sap-security-patch-day-april-2018/https://launchpad.support.sap.com/#/notes/2595800http://www.securityfocus.com/bid/103727https://blogs.sap.com/2018/04/10/sap-security-patch-day-april-2018/https://launchpad.support.sap.com/#/notes/2595800
2018-04-10
Published