9.3

CVE-2023-32113

Information Disclosure vulnerability in SAP GUI for Windows

SAP GUI for Windows - version 7.70, 8.0, allows an unauthorized attacker to gain NTLM authentication information of a victim by tricking it into clicking a prepared shortcut file. Depending on the authorizations of the victim, the attacker can read and modify potentially sensitive information after successful exploitation.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAP ≫ Gui For Windows Version < 7.70
SAP ≫ Gui For Windows Version 7.70 Update -
SAP ≫ Gui For Windows Version 7.70 Update patch_level1
SAP ≫ Gui For Windows Version 7.70 Update patch_level10
SAP ≫ Gui For Windows Version 7.70 Update patch_level11
SAP ≫ Gui For Windows Version 7.70 Update patch_level2
SAP ≫ Gui For Windows Version 7.70 Update patch_level3
SAP ≫ Gui For Windows Version 7.70 Update patch_level4
SAP ≫ Gui For Windows Version 7.70 Update patch_level5
SAP ≫ Gui For Windows Version 7.70 Update patch_level6
SAP ≫ Gui For Windows Version 7.70 Update patch_level7
SAP ≫ Gui For Windows Version 7.70 Update patch_level8
SAP ≫ Gui For Windows Version 7.70 Update patch_level9
SAP ≫ Gui For Windows Version 8.0 Update -
SAP ≫ Gui For Windows Version 8.0 Update patch_level1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.53% 0.404
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 2.8 5.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
SAP 7.5 1.2 5.8
CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
Vendor Advisory
https://launchpad.support.sap.com/#/notes/3320467
Vendor Advisory
Permissions Required