VDB
CVE-2022-35293
CVE-2022-35293
PUBLISHED
CVSS 9.100000381469727 CRITICAL
Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account. On successful exploitation, an attacker can view or modify user data causing limited impact on confidentiality and integrity of the application.
EPSS 0.66% · 71.6th percentile
Risk Scores
CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
0.66%
71.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| SAP SE | SAP Enable Now Manager | 1.0 |
| sap | enable_now_manager | 1.0 |
Exploit Intelligence
Timeline
- Aug 9, 2022 CVE Published
- Aug 10, 2022 EPSS Score
- Sep 25, 2022 EPSS Score
- Nov 10, 2022 EPSS Score
- Dec 27, 2022 EPSS Score
- Feb 11, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 29, 2023 EPSS Score
- May 14, 2023 EPSS Score
- Jun 29, 2023 EPSS Score
- Aug 14, 2023 EPSS Score
- Sep 30, 2023 EPSS Score