Low severity3.3NVD Advisory· Published Mar 10, 2020· Updated Jun 17, 2026
CVE-2020-6197
CVE-2020-6197
Description
SAP Enable Now, before version 1908, does not invalidate session tokens in a timely manner. The Insufficient Session Expiration may allow attackers with local access, for instance, to still download the portables.
Affected products
3cpe:2.3:a:sap:enable_now:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:sap:enable_now:*:*:*:*:*:*:*:*range: <1908
- (no CPE)range: <1908
- SAP SE/SAP Enable Nowv5Range: < before version 1908
Patches
Vulnerability mechanics
References
2- wiki.scn.sap.com/wiki/pages/viewpage.actionnvdVendor Advisory
- launchpad.support.sap.comnvdPermissions Required
News mentions
0No linked articles in our index yet.