CVE-2022-35293
Critical · CVSS 9.1SAP Enable Now — Insecure Session Management / Missing Authorization (CWE-862)
- CVSS
- 9.1
- nvd
- EPSS
- 0.63%
- 45th pct
- KEV
- No
- Class
- other
- CWE-862
Description
Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account. On successful exploitation, an attacker can view or modify user data causing limited impact on confidentiality and integrity of the application.
Search profile — drives PoC discovery
Symbols session managementunauthenticated accessaccount takeoverSAP Enable Now3210566
Keywords CVE-2022-35293SAP Enable Nowinsecure session managementmissing authorizationunauthenticated attackeraccount accessSAP Note 3210566CWE-862
Versions: <UNKNOWN>
References
Status: enriched · ingested 2026-06-23T18:00:15.000Z · profiled 2026-06-24T06:30:26.000Z