CVE-2024-39600

Under certain conditions, the memory of SAP GUI for Windows contains the password used to log on to an SAP system, which might allow an attacker to get hold of the password and impersonate the affected user. As a result, it has a high impact on the confidentiality but there is no impact on the integrity and availability.
References
Link Resource
https://me.sap.com/notes/3461110 Permissions Required
https://me.sap.com/notes/3461110 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory
https://url.sap/sapsecuritypatchday Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:sap:gui_for_windows:8.0:*:*:*:*:*:*:*

History

22 Jan 2025, 18:33

Type Values Removed Values Added
CPE cpe:2.3:a:sap:gui_for_windows:8.0:*:*:*:*:*:*:*
CWE CWE-200 NVD-CWE-Other
First Time Sap gui For Windows
Sap
References () https://url.sap/sapsecuritypatchday - () https://url.sap/sapsecuritypatchday - Vendor Advisory
References () https://me.sap.com/notes/3461110 - () https://me.sap.com/notes/3461110 - Permissions Required
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.2

09 Jul 2024, 05:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-09 05:15

Updated : 2025-01-22 18:33


NVD link : CVE-2024-39600

Mitre link : CVE-2024-39600


JSON object : View

Products Affected

sap

  • gui_for_windows