2024-04-04 08:46:00 +00:00

87 lines
2.6 KiB
JSON

{
"id": "CVE-2022-41209",
"sourceIdentifier": "cna@sap.com",
"published": "2022-10-11T21:15:26.523",
"lastModified": "2023-11-07T03:52:44.107",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses encryption method which lacks proper diffusion and does not hide the patterns well. This can lead to information disclosure. In certain scenarios, application might also be susceptible to replay attacks.\n\n"
},
{
"lang": "es",
"value": "SAP Customer Data Cloud (Gigya mobile app for Android) - versi\u00f3n 7.4, usa un m\u00e9todo de encriptaci\u00f3n que carece de una difusi\u00f3n apropiada y no oculta bien los patrones. Esto puede conllevar a una divulgaci\u00f3n de informaci\u00f3n. En determinados escenarios, la aplicaci\u00f3n tambi\u00e9n podr\u00eda ser susceptible de ataques de repetici\u00f3n"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N",
"attackVector": "PHYSICAL",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "LOW",
"availabilityImpact": "NONE",
"baseScore": 5.2,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 0.9,
"impactScore": 4.2
}
]
},
"weaknesses": [
{
"source": "cna@sap.com",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-326"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:sap:customer_data_cloud:7.4:*:*:*:*:android:*:*",
"matchCriteriaId": "1892A616-7928-43CF-BB88-B9E03C2E6755"
}
]
}
]
}
],
"references": [
{
"url": "https://launchpad.support.sap.com/#/notes/3248970",
"source": "cna@sap.com",
"tags": [
"Permissions Required",
"Vendor Advisory"
]
},
{
"url": "https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html",
"source": "cna@sap.com",
"tags": [
"Vendor Advisory"
]
}
]
}