CVE-2020-6178 - CERT CVE
ID CVE-2020-6178
Sažetak SAP Enable Now, before version 1911, sends the Session ID cookie value in URL. This might be stolen from the browser history or log files, leading to Information Disclosure.
Reference
CVSS
Base: 5.5
Impact: 4.9
Exploitability:8.0
Pristup
VektorSloženostAutentikacija
NETWORK LOW SINGLE
Impact
PovjerljivostCjelovitostDostupnost
PARTIAL PARTIAL NONE
CVSS vektor AV:N/AC:L/Au:S/C:P/I:P/A:N
Zadnje važnije ažuriranje 21-07-2021 - 11:39
Objavljeno 10-03-2020 - 21:15