Back to search
CVE-2019-0341
Published: Aug 14, 2019
Modified: Aug 4, 2024
PUBLISHED
Description
The session cookie used by SAP Enable Now, version 1902, does not have the HttpOnly flag set. If an attacker runs script code in the context of the application, he could get access to the session cookie. The session cookie could then be abused to gain access to the application.
| Vendor | Product | Versions |
|---|---|---|
SAP SE | SAP Enable Now | affected < 1902 |
References
https://launchpad.support.sap.com/#/notes/2794742
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now