First published: Tue Mar 10 2020(Updated: )
SAP Enable Now, before version 1911, sends the Session ID cookie value in URL. This might be stolen from the browser history or log files, leading to Information Disclosure.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Enable Now | <1911 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-6178 is a vulnerability that affects SAP Enable Now before version 1911, where the Session ID cookie value is sent in the URL, which can be stolen from the browser history or log files, leading to information disclosure.
The severity of CVE-2020-6178 is medium, with a severity value of 5.4.
CVE-2020-6178 can be exploited by an attacker stealing the Session ID cookie value from the URL in the browser history or log files.
SAP Enable Now before version 1911 is affected by CVE-2020-6178.
To mitigate CVE-2020-6178, update to SAP Enable Now version 1911 or later.