Description
SAP Enable Now, before version 1908, does not invalidate session tokens in a timely manner. The Insufficient Session Expiration may allow attackers with local access, for instance, to still download the portables.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_misc
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=540935305
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2845363
Scores
CVSS v3
3.3
EPSS
0.0021
EPSS Percentile
43.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Details
CWE
CWE-613
Status
published
Products (1)
sap/enable_now
< 1908
Published
Mar 10, 2020
Tracked Since
Feb 18, 2026