CVE-2020-6197

Publication date

2020-03-10 20:17:58

Family

sap

State

PUBLISHED

Description

SAP Enable Now, before version 1908, does not invalidate session tokens in a timely manner. The Insufficient Session Expiration may allow attackers with local access, for instance, to still download the portables.