{ "data_version": "4.0", "data_type": "CVE", "data_format": "MITRE", "CVE_data_meta": { "ID": "CVE-2024-39600", "ASSIGNER": "cna@sap.com", "STATE": "PUBLIC" }, "description": { "description_data": [ { "lang": "eng", "value": "Under certain conditions, the memory of SAP GUI\nfor Windows contains the password used to log on to an SAP system, which might\nallow an attacker to get hold of the password and impersonate the affected\nuser. As a result, it has a high impact on the confidentiality but there is no\nimpact on the integrity and availability." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "CWE-200: Exposure of Sensitive Information to an Unauthorized Actor", "cweId": "CWE-200" } ] } ] }, "affects": { "vendor": { "vendor_data": [ { "vendor_name": "SAP_SE", "product": { "product_data": [ { "product_name": "SAP GUI for Windows", "version": { "version_data": [ { "version_affected": "=", "version_value": "BC-FES-GUI 8" } ] } } ] } } ] } }, "references": { "reference_data": [ { "url": "https://url.sap/sapsecuritypatchday", "refsource": "MISC", "name": "https://url.sap/sapsecuritypatchday" }, { "url": "https://me.sap.com/notes/3461110", "refsource": "MISC", "name": "https://me.sap.com/notes/3461110" } ] }, "generator": { "engine": "Vulnogram 0.2.0" }, "source": { "discovery": "UNKNOWN" }, "impact": { "cvss": [ { "attackComplexity": "HIGH", "attackVector": "LOCAL", "availabilityImpact": "NONE", "baseScore": 5, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "HIGH", "scope": "CHANGED", "userInteraction": "REQUIRED", "vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N", "version": "3.1" } ] } }