Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mqx7-r2mm-q7pp

Опубликовано: 14 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 6

Описание

SAP GUI for Windows stores user input on the client PC to improve usability. Under very specific circumstances an attacker with administrative privileges or access to the victim�s user directory on the Operating System level would be able to read this data. Depending on the user input provided in transactions, the disclosed data could range from non-critical data to highly sensitive data, causing high impact on confidentiality of the application.

SAP GUI for Windows stores user input on the client PC to improve usability. Under very specific circumstances an attacker with administrative privileges or access to the victim�s user directory on the Operating System level would be able to read this data. Depending on the user input provided in transactions, the disclosed data could range from non-critical data to highly sensitive data, causing high impact on confidentiality of the application.

EPSS

Процентиль: 10%
0.00035
Низкий

6 Medium

CVSS3

Дефекты

CWE-497

Связанные уязвимости

CVSS3: 6
nvd
около 1 года назад

SAP GUI for Windows stores user input on the client PC to improve usability. Under very specific circumstances an attacker with administrative privileges or access to the victim�s user directory on the Operating System level would be able to read this data. Depending on the user input provided in transactions, the disclosed data could range from non-critical data to highly sensitive data, causing high impact on confidentiality of the application.

CVSS3: 6
fstec
больше 1 года назад

Уязвимость графического интерфейса пользователя SAP GUI для Windows, связанная с раскрытием системных данных неавторизованной для контролируемой области, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 10%
0.00035
Низкий

6 Medium

CVSS3

Дефекты

CWE-497