CVE-2022-35293 PUBLISHED CVSS 9.100000381469727 CRITICAL

Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account. On successful exploitation, an attacker can view or modify user data causing limited impact on confidentiality and integrity of the application.

EPSS 0.66% · 71.0th percentile

Risk Scores

CVSS v3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
0.66%
71.0th percentile

Affected Products

VendorProductVersions
SAP SESAP Enable Now Manager1.0
sapenable_now_manager1.0

Timeline

References

Open in Interactive Console →