CVE-2023-36920
MEDIUMSAP Enable Now - WPB_MANAGER <1.0-ENABLE_NOW_CONSUMP_DEL 1704 - XSS
Title source: llmDescription
In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-FRAME-OPTIONS response header is not implemented, allowing an unauthenticated attacker to attempt clickjacking, which could result in disclosure or modification of information.
Scores
CVSS v3
6.1
EPSS
0.0011
EPSS Percentile
28.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1021
Status
published
Products (4)
sap/enable_now_enable_now_consump_del
1704
sap/enable_now_wpb_manager
1.0
sap/enable_now_wpb_manager_ce
10
sap/enable_now_wpb_manager_hana
10
Published
Oct 30, 2023
Tracked Since
Feb 18, 2026