Vulnerability Description
Under certain circumstances SAP Dynamic Authorization Management (DAM) by NextLabs (Java Policy Controller versions 7.7 and 8.5) exposes sensitive information in the application logs.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Dynamic Authorization Management | 7.7 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/2664767Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=497256000Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2664767Permissions RequiredVendor Advisory
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=497256000Vendor Advisory
FAQ
What is CVE-2018-2440?
CVE-2018-2440 is a vulnerability with a CVSS score of 4.4 (MEDIUM). Under certain circumstances SAP Dynamic Authorization Management (DAM) by NextLabs (Java Policy Controller versions 7.7 and 8.5) exposes sensitive information in the application logs.
How severe is CVE-2018-2440?
CVE-2018-2440 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-2440?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Dynamic Authorization Management.