CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2022-35293

Critical · CVSS 9.1

SAP Enable Now — Insecure Session Management / Missing Authorization (CWE-862)

CVSS
9.1
nvd
EPSS
0.63%
45th pct
KEV
No
Class
other
CWE-862

Description

Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account. On successful exploitation, an attacker can view or modify user data causing limited impact on confidentiality and integrity of the application.

Search profile — drives PoC discovery

Symbols session managementunauthenticated accessaccount takeoverSAP Enable Now3210566
Keywords CVE-2022-35293SAP Enable Nowinsecure session managementmissing authorizationunauthenticated attackeraccount accessSAP Note 3210566CWE-862
Versions: <UNKNOWN>

References

Status: enriched · ingested 2026-06-23T18:00:15.000Z · profiled 2026-06-24T06:30:26.000Z