CVE-2020-6291Insufficient Session Expiration in SE SAP Disclosure Management

Severity
8.8HIGHNVD
EPSS
0.2%
top 63.93%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 14
Latest updateMay 24

Description

SAP Disclosure Management, version 10.1, session mechanism does not have expiration data set therefore allows unlimited access after authenticating once, leading to Insufficient Session Expiration

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-9qx8-h7w2-x7mp: SAP Disclosure Management, version 102022-05-24
CVEList
CVE-2020-6291: SAP Disclosure Management, version 102020-07-14
CVE-2020-6291 — Insufficient Session Expiration | cvebase