CVE-2020-6178
CVE-2020-6178
SAP Enable Now, before version 1911, sends the Session ID cookie value in URL. This might be stolen from the browser history or log files, leading to Information Disclosure.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Affected products
SAP SE · SAP Enable NowWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →