Arbitrary Application Vulnerability in SAP Fiori Client
CVE-2018-2489

7.8HIGH

Key Information:

Vendor
SAP
Vendor
CVE Published:
13 November 2018

Summary

An arbitrary Android application can delete the Single Sign-On (SSO) configuration of the SAP Fiori Client without requiring permission. This security risk underscores the importance of updating to the latest version, specifically SAP Fiori Client version 1.11.5, available on the Google Play Store, to mitigate potential threats and secure user data.

Affected Version(s)

SAP Fiori Client < 1.11.5

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.