First published: Wed Dec 11 2019(Updated: )
SAP Enable Now, before version 1911, leaks information about the existence of a particular user which can be used to construct a list of users, leading to a user enumeration vulnerability and Information Disclosure.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Enable Now | <1911 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-0405.
CVE-2019-0405 has a severity level of 7.5 (high).
SAP Enable Now before version 1911 is affected by CVE-2019-0405.
CVE-2019-0405 poses a user enumeration vulnerability and information disclosure risk.
Yes, you can find more information about CVE-2019-0405 in the following references: [SAP Support note](https://launchpad.support.sap.com/#/notes/2845183) and [SAP SCN Wiki](https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=533660397).