Insufficient Session Expiration in SAP Enable Now by SAP
CVE-2020-6197
3.8LOW
What is CVE-2020-6197?
SAP Enable Now prior to version 1908 has a flaw in its session management where session tokens are not invalidated promptly. This allows an attacker with local access to potentially exploit the session and download sensitive portables, posing a significant risk to data security and user privacy.
Affected Version(s)
SAP Enable Now < before version 1908