CVE Published: 09/07/2024 |
CVE Updated: 02/08/2024 |
CVE Year: 2024 Source: sap |
Vendor: SAP_SE |
Product: SAP GUI for Windows Status : PUBLISHED
CVE-2024-39600 Description
Under certain conditions, the memory of SAP GUI
for Windows contains the password used to log on to an SAP system, which might
allow an attacker to get hold of the password and impersonate the affected
user. As a result, it has a high impact on the confidentiality but there is no
impact on the integrity and availability.
Metrics
CVSS Version: 3.1 |
Base Score: 5 MEDIUM Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N
l➤ Exploitability Metrics: Attack Vector (AV)* LOCAL Attack Complexity (AC)* HIGH Privileges Required (PR)* HIGH User Interaction (UI)* REQUIRED Scope (S)* CHANGED