VDB

CVE-2022-35293

CVE-2022-35293 PUBLISHED CVSS 9.100000381469727 CRITICAL

Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account. On successful exploitation, an attacker can view or modify user data causing limited impact on confidentiality and integrity of the application.

EPSS 0.66% · 71.6th percentile

Risk Scores

CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
0.66%
71.6th percentile

Affected Products

VendorProductVersions
SAP SESAP Enable Now Manager1.0
sapenable_now_manager1.0

Timeline

  • Aug 9, 2022 CVE Published
  • Aug 10, 2022 EPSS Score
  • Sep 25, 2022 EPSS Score
  • Nov 10, 2022 EPSS Score
  • Dec 27, 2022 EPSS Score
  • Feb 11, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 29, 2023 EPSS Score
  • May 14, 2023 EPSS Score
  • Jun 29, 2023 EPSS Score
  • Aug 14, 2023 EPSS Score
  • Sep 30, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›