CVE-2020-6197

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/03/2020
Last modified:
12/03/2020

Description

SAP Enable Now, before version 1908, does not invalidate session tokens in a timely manner. The Insufficient Session Expiration may allow attackers with local access, for instance, to still download the portables.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sap:enable_now:*:*:*:*:*:*:*:* 1908 (excluding)