CVE-2020-6178 Information
Feb 14, 2021
cve
Description
SAP Enable Now before version 1911 sends the Session ID cookie value in URL. This might be stolen from the browser history or log files leading to Information Disclosure.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Reference
https://launchpad.support.sap.com//notes/2880664 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=540935305
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
5.4
Share on: