- EPSS 0.03%
- Published 11.02.2025 01:15:11
- Last modified 18.02.2025 18:15:33
SAP GUI for Windows & RFC service credentials are incorrectly stored in the memory of the program allowing an unauthenticated attacker to access information within systems, resulting in privilege escalation. On successful exploitation, this could res...
- EPSS 0.03%
- Published 14.01.2025 01:15:15
- Last modified 14.01.2025 01:15:15
SAP GUI for Windows stores user input on the client PC to improve usability. Under very specific circumstances an attacker with administrative privileges or access to the victim�s user directory on the Operating System level would be able to read thi...
CVE-2024-39600
- EPSS 0.06%
- Published 09.07.2024 05:15:13
- Last modified 22.01.2025 18:33:47
Under certain conditions, the memory of SAP GUI for Windows contains the password used to log on to an SAP system, which might allow an attacker to get hold of the password and impersonate the affected user. As a result, it has a high impact on the c...
CVE-2023-32113
- EPSS 0.18%
- Published 09.05.2023 02:15:12
- Last modified 21.11.2024 08:02:44
SAP GUI for Windows - version 7.70, 8.0, allows an unauthorized attacker to gain NTLM authentication information of a victim by tricking it into clicking a prepared shortcut file. Depending on the authorizations of the victim, the attacker can read a...
CVE-2021-40503
- EPSS 0.1%
- Published 10.11.2021 16:15:08
- Last modified 21.11.2024 06:24:16
An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an attacker with sufficient privileges on the local client-side PC to obtain an equivalent of the user’s password. With this highly s...
CVE-2021-27612
- EPSS 0.18%
- Published 11.05.2021 15:15:08
- Last modified 21.11.2024 05:58:17
In specific situations SAP GUI for Windows until and including 7.60 PL9, 7.70 PL0, forwards a user to specific malicious website which could contain malware or might lead to phishing attacks to steal credentials of the victim.
CVE-2017-6950
- EPSS 1.18%
- Published 23.03.2017 20:59:00
- Last modified 20.04.2025 01:37:25
SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAP code, aka SAP Security Note 2407616.