ZeroHour

CVE-2023-36920

CVSS 3.1
6.1 medium
EPSS
<1%p28
Published
()
Modified
Description

In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-FRAME-OPTIONS response header is not implemented, allowing an unauthenticated attacker to attempt clickjacking, which could result in disclosure or modification of information.

Vendors
sap
Products
enable now enable now consump del, enable now wpb manager, enable now wpb manager ce, enable now wpb manager hana
Weakness
CWE-1021
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.