Vulnerability Name: | CCN-105543 | ||||||
Published: | 2015-08-12 | ||||||
Updated: | 2015-08-12 | ||||||
Summary: | SAP Mobile Platform could allow a local attacker to obtain sensitive information, caused by the use of predictable passwords for secure storage by the DataVault API. An attacker could exploit this vulnerability to obtain encrypted credentials and other sensitive information. | ||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) 3.5 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||
CVSS v2 Severity: | 2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
| ||||||
Vulnerability Consequences: | Obtain Information | ||||||
References: | Source: CCN Type: Full Disclosure Mailing List, Wed, 12 Aug 2015 11:52:17 -0300 [Onapsis Security Advisory 2015-012] SAP Mobile Platform DataVault Predictable Encryption Password for Secure Storage Source: XF Type: UNKNOWN sap-mobile-databult-info-disc(105543) Source: CCN Type: SAP Web site SAP Security Notes 2094830 | ||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||
BACK |