Vulnerability Description
SAP Enable Now, before version 1908, does not invalidate session tokens in a timely manner. The Insufficient Session Expiration may allow attackers with local access, for instance, to still download the portables.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Enable Now | < 1908 |
Related Weaknesses (CWE)
References
- https://launchpad.support.sap.com/#/notes/2845363Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=540935305Vendor Advisory
- https://launchpad.support.sap.com/#/notes/2845363Permissions Required
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=540935305Vendor Advisory
FAQ
What is CVE-2020-6197?
CVE-2020-6197 is a vulnerability with a CVSS score of 3.3 (LOW). SAP Enable Now, before version 1908, does not invalidate session tokens in a timely manner. The Insufficient Session Expiration may allow attackers with local access, for instance, to still download t...
How severe is CVE-2020-6197?
CVE-2020-6197 has been rated LOW with a CVSS base score of 3.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-6197?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Enable Now.