PT-2019-4452 · Sap · Sap Enable Now

Published

2019-08-13

·

Updated

2020-08-24

·

CVE-2019-0341

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP Enable Now version 1902
Description The issue is related to the session cookie used by the application, which does not have the HttpOnly flag set. This allows an attacker who runs script code in the context of the application to access the session cookie, potentially leading to unauthorized access to the application. The vulnerability is also described as being related to insufficient input validation when implementing the session cookie, which could allow a remote attacker to gain unauthorized access to protected information.
Recommendations For SAP Enable Now version 1902, consider setting the HttpOnly flag for the session cookie to prevent JavaScript access. As a temporary workaround, restrict access to sensitive areas of the application to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00239
CVE-2019-0341

Affected Products

Sap Enable Now