9.3
CVE-2023-32113
- EPSS 0.53%
- Veröffentlicht 09.05.2023 02:15:12
- Zuletzt bearbeitet 21.11.2024 08:02:44
- Erkennungen
Information Disclosure vulnerability in SAP GUI for Windows
SAP GUI for Windows - version 7.70, 8.0, allows an unauthorized attacker to gain NTLM authentication information of a victim by tricking it into clicking a prepared shortcut file. Depending on the authorizations of the victim, the attacker can read and modify potentially sensitive information after successful exploitation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Gui For Windows Version < 7.70
SAP ≫ Gui For Windows Version 7.70 Update -
SAP ≫ Gui For Windows Version 7.70 Update patch_level1
SAP ≫ Gui For Windows Version 7.70 Update patch_level10
SAP ≫ Gui For Windows Version 7.70 Update patch_level11
SAP ≫ Gui For Windows Version 7.70 Update patch_level2
SAP ≫ Gui For Windows Version 7.70 Update patch_level3
SAP ≫ Gui For Windows Version 7.70 Update patch_level4
SAP ≫ Gui For Windows Version 7.70 Update patch_level5
SAP ≫ Gui For Windows Version 7.70 Update patch_level6
SAP ≫ Gui For Windows Version 7.70 Update patch_level7
SAP ≫ Gui For Windows Version 7.70 Update patch_level8
SAP ≫ Gui For Windows Version 7.70 Update patch_level9
SAP ≫ Gui For Windows Version 8.0 Update -
SAP ≫ Gui For Windows Version 8.0 Update patch_level1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.53% | 0.404 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.3 | 2.8 | 5.8 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
|
| SAP | 7.5 | 1.2 | 5.8 |
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
https://launchpad.support.sap.com/#/notes/3320467