CVE Database
/

CVE-2021-40503

Back to search

CVE-2021-40503

Published: Nov 10, 2021

Modified: Aug 4, 2024

PUBLISHED

Description

An information disclosure vulnerability exists in SAP GUI for Windows - versions < 7.60 PL13, 7.70 PL4, which allows an attacker with sufficient privileges on the local client-side PC to obtain an equivalent of the user’s password. With this highly sensitive data leaked, the attacker would be able to logon to the backend system the SAP GUI for Windows was connected to and launch further attacks depending on the authorizations of the user.

VendorProductVersions

SAP SE

SAP GUI for Windows

affected
< 7.60 PL13
affected
< 7.70 PL4

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now