Information Disclosure vulnerability in Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge)
CVE-2024-22125
7.4HIGH
Key Information:
- Vendor
- SAP
- Vendor
- CVE Published:
- 9 January 2024
Summary
The Microsoft Edge browser extension for the SAP GUI connector, version 1.0, is vulnerable under specific conditions, allowing attackers to obtain access to sensitive information that should be restricted. This vulnerability raises significant concerns regarding data confidentiality and may lead to unauthorized exposure of sensitive organizational data. Users and organizations are advised to apply necessary mitigations and ensure their systems are updated to mitigate potential risks.
Affected Version(s)
Microsoft Edge browser extension (SAP GUI connector for Microsoft Edge) 1.0
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved