CVE-2022-35293: Critical severity SAP Enable Now Manager vulnerability
Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account. On successful exploitation, an attacker can view or modify user data causing limited impact on confidentiality and integrity of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-35293?
CVE-2022-35293 has a limited impact on confidentiality and integrity due to insecure session management in SAP Enable Now.
How do I fix CVE-2022-35293?
To fix CVE-2022-35293, apply the latest patches provided by SAP for Enable Now Manager version 1.0.
Who is affected by CVE-2022-35293?
CVE-2022-35293 affects users of SAP Enable Now Manager version 1.0 who have not implemented security measures for session management.
What type of attack does CVE-2022-35293 enable?
CVE-2022-35293 enables an unauthenticated attacker to gain access to user accounts through insecure session management.
What impact does CVE-2022-35293 have on user data?
Upon successful exploitation of CVE-2022-35293, an attacker can view or modify user data.