VYPR
High severity8.3NVD Advisory· Published Nov 13, 2018· Updated Jun 17, 2026

CVE-2018-2487

CVE-2018-2487

Description

SAP Disclosure Management 10.x allows an attacker to exploit through a specially crafted zip file provided by users: When extracted in specific use cases, files within this zip file can land in different locations than the originally intended extraction point.

Affected products

3
  • SAP/SAP Disclosure Managementv5
    Range: = 10.X
  • SAP/Disclosure Managementllm-fuzzy2 versions
    10.x+ 1 more
    • (no CPE)range: 10.x
    • cpe:2.3:a:sap:disclosure_management:10.1:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.