Information Disclosure Vulnerability in SAP Enable Now by SAP
CVE-2021-27637
5.9MEDIUM
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 9 June 2021
Summary
An information disclosure vulnerability exists in SAP Enable Now (SAP Workforce Performance Builder - Manager), allowing unauthorized access to restricted information under specific conditions. This can lead to inadvertent exposure of sensitive data, enabling attackers to gain insights into confidential operations and processes. Organizations using affected versions should assess their security posture and apply relevant protective measures to mitigate potential risks.
Affected Version(s)
SAP Enable Now (SAP Workforce Performance Builder - Manager) < 1.0 < 1.0
SAP Enable Now (SAP Workforce Performance Builder - Manager) < 10 < 10
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved