Information Disclosure Vulnerability in SAP GUI for Windows
CVE-2021-40503

7.8HIGH

Key Information:

Vendor
SAP
Vendor
CVE Published:
10 November 2021

Summary

An information disclosure vulnerability exists in SAP GUI for Windows prior to the specified versions, which can allow a local attacker with sufficient privileges to gain access to sensitive user information, including the user's password. This exposure provides the attacker the ability to access the connected backend system, posing significant security risks depending on the user's authorization levels.

Affected Version(s)

SAP GUI for Windows < 7.60 PL13 < 7.60 PL13

SAP GUI for Windows < 7.70 PL4 < 7.70 PL4

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.