Task Hijacking Vulnerability in Android Applications by SAP
CVE-2021-33699
7.6HIGH
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 10 August 2021
Summary
This vulnerability arises from a misconfiguration in the AndroidManifest.xml affecting task control features in SAP applications on Android devices. It enables unauthorized attackers to hijack legitimate applications, potentially leading to data breaches and exploitation of sensitive user information. Proper configuration and security measures must be implemented to mitigate this risk.
Affected Version(s)
SAP Fiori Client Native Mobile for Android < 3.2
References
CVSS V3.1
Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved