Credential Spoofing Vulnerability in SAP GUI for Windows by SAP
CVE-2021-21448

5.3MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
12 January 2021

Summary

The SAP GUI for Windows version 7.60 has a vulnerability that allows a local attacker to spoof logon credentials for Application Server ABAP backend systems. This occurs in the client PC's memory and can lead to unauthorized access to restricted information. The attacker needs to possess the operating system authorization of the victim, as the exploit cannot be executed over the network, highlighting the importance of local security measures.

Affected Version(s)

SAP GUI FOR WINDOWS < 7.60

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.