SAP Enable Now, before version 1911, sends the Session ID cookie value in URL. This might be stolen from the browser history or log files, leading to Information Disclosure.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published: 2020-03-10T20:17:39

Updated: 2024-08-04T08:55:22.177Z

Reserved: 2020-01-08T00:00:00

Link: CVE-2020-6178

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-03-10T21:15:13.637

Modified: 2021-07-21T11:39:23.747

Link: CVE-2020-6178

cve-icon Redhat

No data.