Information Disclosure Vulnerability in SAP GUI for Windows
CVE-2021-40503
7.8HIGH
Summary
An information disclosure vulnerability exists in SAP GUI for Windows prior to the specified versions, which can allow a local attacker with sufficient privileges to gain access to sensitive user information, including the user's password. This exposure provides the attacker the ability to access the connected backend system, posing significant security risks depending on the user's authorization levels.
Affected Version(s)
SAP GUI for Windows < 7.60 PL13 < 7.60 PL13
SAP GUI for Windows < 7.70 PL4 < 7.70 PL4
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved