Information Disclosure Vulnerability in SAP Enable Now by SAP
CVE-2021-27637

5.9MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
9 June 2021

Summary

An information disclosure vulnerability exists in SAP Enable Now (SAP Workforce Performance Builder - Manager), allowing unauthorized access to restricted information under specific conditions. This can lead to inadvertent exposure of sensitive data, enabling attackers to gain insights into confidential operations and processes. Organizations using affected versions should assess their security posture and apply relevant protective measures to mitigate potential risks.

Affected Version(s)

SAP Enable Now (SAP Workforce Performance Builder - Manager) < 1.0 < 1.0

SAP Enable Now (SAP Workforce Performance Builder - Manager) < 10 < 10

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.