Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fg6q-x7qr-4pp3

Опубликовано: 30 окт. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 6.1

Описание

In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-FRAME-OPTIONS response header is not implemented, allowing an unauthenticated attacker to attempt clickjacking, which could result in disclosure or modification of information.

In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-FRAME-OPTIONS response header is not implemented, allowing an unauthenticated attacker to attempt clickjacking, which could result in disclosure or modification of information.

EPSS

Процентиль: 30%
0.00109
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-1021

Связанные уязвимости

CVSS3: 6.1
nvd
больше 2 лет назад

In SAP Enable Now - versions WPB_MANAGER 1.0, WPB_MANAGER_CE 10, WPB_MANAGER_HANA 10, ENABLE_NOW_CONSUMP_DEL 1704, the X-FRAME-OPTIONS response header is not implemented, allowing an unauthenticated attacker to attempt clickjacking, which could result in disclosure or modification of information.

EPSS

Процентиль: 30%
0.00109
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-1021