SAP Enable Now, before version 1911, leaks information about the existence of a particular user which can be used to construct a list of users, leading to a user enumeration vulnerability and Information Disclosure.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NSap Enable Now
APPSap< 1911
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2019-0403CRITICAL9.8PL ✓same product
CSV Command Injection w SAP Enable Now przed wersją 1911
CVE-2019-0404HIGH7.5same product
SAP Enable Now, before version 1911, leaks information about network configuration in the server error message...
CVE-2019-0341HIGH8.8same product
The session cookie used by SAP Enable Now, version 1902, does not have the HttpOnly flag set. If an attacker r...
CVE-2023-33988MEDIUM6.1same product
In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1...
CVE-2023-36918MEDIUM6.1same product
In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1...