cbcvebase.
CVE-2020-6290
published 2020-07-14

CVE-2020-6290: SAP Disclosure Management, version 10.1, is vulnerable to Session Fixation attacks wherein the attacker tricks the user into using a specific session ID.

medium6.3CVSS 3.1
AVNACLPRNUIRSUCLILAL
SAP Disclosure Management, version 10.1, is vulnerable to Session Fixation attacks wherein the attacker tricks the user into using a specific session ID.

Affected

2 ranges
VendorProductVersion rangeFixed in
sapdisclosure_management
sap_sesap_disclosure_management< 1.01.0