PT-2019-4452 · Sap · Sap Enable Now
Published
2019-08-13
·
Updated
2020-08-24
·
CVE-2019-0341
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP Enable Now version 1902
Description
The issue is related to the session cookie used by the application, which does not have the HttpOnly flag set. This allows an attacker who runs script code in the context of the application to access the session cookie, potentially leading to unauthorized access to the application. The vulnerability is also described as being related to insufficient input validation when implementing the session cookie, which could allow a remote attacker to gain unauthorized access to protected information.
Recommendations
For SAP Enable Now version 1902, consider setting the HttpOnly flag for the session cookie to prevent JavaScript access. As a temporary workaround, restrict access to sensitive areas of the application to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Permission
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap Enable Now