Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Insecure Key & Secret Management vulnerability in SAP GUI for Windows
Vulnerability Description
SAP GUI for Windows & RFC service credentials are incorrectly stored in the memory of the program allowing an unauthenticated attacker to access information within systems, resulting in privilege escalation. On successful exploitation, this could result in disclosure of highly sensitive information. This has no impact on integrity, and availability.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
在没有访问控制机制中存储敏感数据
Vulnerability Title
SAP GUI 安全漏洞
Vulnerability Description
SAP GUI是德国思爱普(SAP)公司的一个应用软件。SAP系统的图形用户界面。 SAP GUI存在安全漏洞,该漏洞源于凭证被错误地存储在程序内存中。攻击者利用该漏洞可以访问系统内的信息,从而升级权限。
CVSS Information
N/A
Vulnerability Type
N/A