---
id: CVE-2022-35293
title: >-
  Due to insecure session management, SAP Enable Now allows an unauthenticated
  attacker to gain access to user's account
summary: >-
  Due to insecure session management, SAP Enable Now allows an unauthenticated
  attacker to gain access to user's account. On successful exploitation, an
  attacker can view or modify user data causing limited impact on
  confidentiality and in…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-862
vendor: sap
product: enable_now_manager
affected:
  - enable_now_manager = 1.0
published: '2022-08-10'
updated: '2026-06-23'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-35293'
references:
  - url: 'https://launchpad.support.sap.com/#/notes/3210566'
    label: cna@sap.com
  - url: >-
      https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
    label: cna@sap.com
  - url: 'https://launchpad.support.sap.com/#/notes/3210566'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00743
epssPercentile: 0.52792
ingestedAt: '2026-06-29T13:24:33.498Z'
---

## Overview

Due to insecure session management, SAP Enable Now allows an unauthenticated attacker to gain access to user's account. On successful exploitation, an attacker can view or modify user data causing limited impact on confidentiality and integrity of the application.

## Affected

- `enable_now_manager = 1.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
