Vulnerabilities > CVE-2020-6178 - Insufficient Session Expiration vulnerability in SAP Enable NOW 1902/1908

047910
CVSS 5.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
sap
CWE-613

Summary

SAP Enable Now, before version 1911, sends the Session ID cookie value in URL. This might be stolen from the browser history or log files, leading to Information Disclosure.

Vulnerable Configurations

Part Description Count
Application
Sap
3

Common Weakness Enumeration (CWE)