Required CVE Record Information
Description
Improper session management when using SAP Cloud Platform 2.0 (Connectivity Service and Cloud Connector). Under certain conditions, data of some other user may be shown or modified when using an application built on top of SAP Cloud Platform.
CVSS 1 Total
Score | Severity | Version | Vector String |
---|---|---|---|
6.3 | MEDIUM | 3.0 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 3 Total
- securityfocus.com: 103702 vdb-entryx_transferred
- https://blogs.sap.com/2018/04/10/sap-security-patch-day-april-2018/ x_transferred
- https://launchpad.support.sap.com/#/notes/2614141 x_transferred