Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 3326769
was released on
11.07.2023 and deals with
"[Multiple CVEs] Multiple Vulnerabilities in SAP Enable Now" within SAP Enable Now.
We advice you to follow the instructions, to resolve
clickjacking cross-site scripting (xss) information disclosure
with a
medium potential for exploitation
in component KM-SEN-MGR.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as monthly patch process.
Risk specification
SAP Enable Now allows an unauthenticated attacker to exploit either cross-site scripting, or clickjacking resulting in disclosure or modification of information vulnerabilities. See CVE-2023-33988, CVE-2023-36918, CVE-2023-36920 and CVE-2023-36919Solution
Additional security headers were implemented to prevent this kind of attack.
Affected System
SAP Enable Now provides the knowledge your employees need to succeed exactly where and when it’s needed. The product exists for on-premise and cloud applications. A security guide is provided for each facet of the SAP Enable Now product.
The advisory is valid for