CVE-2019-0405: Infoleak
Published Dec 11, 2019
·Updated
SAP Enable Now, before version 1911, leaks information about the existence of a particular user which can be used to construct a list of users, leading to a user enumeration vulnerability and Information Disclosure.
Affected Software
1 affected component
SAP Enable Now<1911
Event History
Dec 11, 2019
CVE Published
via MITRE·09:35 PM
Data Sourced
via MITRE·09:35 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2019-0405.
2
What is the severity level of CVE-2019-0405?
CVE-2019-0405 has a severity level of 7.5 (high).
3
What is affected by CVE-2019-0405?
SAP Enable Now before version 1911 is affected by CVE-2019-0405.
4
What is the risk of CVE-2019-0405?
CVE-2019-0405 poses a user enumeration vulnerability and information disclosure risk.
5
Are there any references for CVE-2019-0405?
Yes, you can find more information about CVE-2019-0405 in the following references: [SAP Support note](https://launchpad.support.sap.com/#/notes/2845183) and [SAP SCN Wiki](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=533660397).