An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an attacker with sufficient privileges on the local client-side PC to obtain an equivalent of the user’s password. With this highly sensitive data leaked, the attacker would be able to logon to the backend system the SAP GUI for Windows was connected to and launch further attacks depending on the authorizations of the user.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-27679 An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an attacker with sufficient privileges on the local client-side PC to obtain an equivalent of the user’s password. With this highly sensitive data leaked, the attacker would be able to logon to the backend system the SAP GUI for Windows was connected to and launch further attacks depending on the authorizations of the user.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2024-08-04T02:44:10.837Z

Reserved: 2021-09-03T00:00:00

Link: CVE-2021-40503

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-11-10T16:15:08.757

Modified: 2024-11-21T06:24:16.697

Link: CVE-2021-40503

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.