Information Disclosure Vulnerabilities in SAP PowerDesigner
CVE-2023-37484

5.3MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
8 August 2023

Summary

SAP PowerDesigner - version 16.7, queries all password hashes in the backend database and compares it with the user provided one during login attempt, which might allow an attacker to access password hashes from the client's memory.

Affected Version(s)

SAP PowerDesigner 16.7

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.