← back
CVE-2020-6178medium

CVE-2020-6178

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.4epss 0.7%
exploitation probability
0.7%top 47% of all CVEs
observed exploitation
nono source reports it
SAP Enable Now, before version 1911, sends the Session ID cookie value in URL. This might be stolen from the browser history or log files, leading to Information Disclosure.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Affected products
SAP SE · SAP Enable Now