VYPR
Medium severity5.4NVD Advisory· Published Mar 10, 2020· Updated Jun 17, 2026

CVE-2020-6178

CVE-2020-6178

Description

SAP Enable Now, before version 1911, sends the Session ID cookie value in URL. This might be stolen from the browser history or log files, leading to Information Disclosure.

Affected products

3
  • SAP/Enable Now2 versions
    cpe:2.3:a:sap:enable_now:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:sap:enable_now:*:*:*:*:*:*:*:*range: <1911
    • (no CPE)range: <1911
  • SAP SE/SAP Enable Nowv5
    Range: < before version 1911

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.