← back
CVE-2020-6178

CVE-2020-6178

CVSS 5.4 MEDIUMEPSS 0.7%
SAP Enable Now, before version 1911, sends the Session ID cookie value in URL. This might be stolen from the browser history or log files, leading to Information Disclosure.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Affected products
SAP SE · SAP Enable Now

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →