Описание
Under certain conditions, SAP Mobile SDK Certificate Provider allows a local unprivileged attacker to exploit an insecure temporary file storage. For a successful exploitation user interaction from another user is required and could lead to complete impact of confidentiality integrity and availability.
Ссылки
- PatchThird Party Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.0.8 (исключая)
cpe:2.3:a:sap:mobile_sdk_certificate_provider:*:*:*:*:*:*:*:*
EPSS
Процентиль: 7%
0.00027
Низкий
7.8 High
CVSS3
7.8 High
CVSS3
6.9 Medium
CVSS2
Дефекты
CWE-668
EPSS
Процентиль: 7%
0.00027
Низкий
7.8 High
CVSS3
7.8 High
CVSS3
6.9 Medium
CVSS2
Дефекты
CWE-668