ZeroHour

CVE-2022-35293

CVSS 3.1
9.1 critical
EPSS
<1%p53
Published
()
Modified
Description

Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account. On successful exploitation, an attacker can view or modify user data causing limited impact on confidentiality and integrity of the application.

Vendors
sap
Products
enable now manager
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.