CVE-2024-39596: SAP SE SAP Enable Now

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

Due to missing authorization checks, SAP Enable Now allows an author to escalate privileges to access information which should otherwise be restricted. On successful exploitation, the attacker can cause limited impact on confidentiality of the application.

Affected products

Published 2024-07-09. Last modified 2026-06-17.