PT-2022-4103 · Sap · Sap Enable Now

Published

2022-08-09

·

Updated

2022-08-15

·

CVE-2022-35293

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SAP Enable Now (affected versions not specified)
Description The issue is related to insecure session management and authorization procedure weaknesses. An unauthenticated attacker can exploit this to gain access to a user's account, potentially viewing or modifying user data. This could have limited impact on the confidentiality and integrity of the application. The vulnerability may allow a remote attacker to gain unauthorized access to protected information and compromise its integrity.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2022-04939
CVE-2022-35293

Affected Products

Sap Enable Now