In specific situations SAP GUI for Windows until and including 7.60 PL9, 7.70 PL0, forwards a user to specific malicious website which could contain malware or might lead to phishing attacks to steal credentials of the victim.
References
Link | Resource |
---|---|
https://launchpad.support.sap.com/#/notes/3023078 | Permissions Required Vendor Advisory |
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=576094655 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
29 Jun 2021, 13:50
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:sap:gui_for_windows:7.70:*:*:*:*:*:*:* |
cpe:2.3:a:sap:gui_for_windows:7.60:patch_level1:*:*:*:*:*:* cpe:2.3:a:sap:gui_for_windows:7.60:patch_level4:*:*:*:*:*:* cpe:2.3:a:sap:gui_for_windows:7.60:patch_level2:*:*:*:*:*:* cpe:2.3:a:sap:gui_for_windows:7.60:patch_level3:*:*:*:*:*:* cpe:2.3:a:sap:gui_for_windows:7.60:-:*:*:*:*:*:* cpe:2.3:a:sap:gui_for_windows:7.60:patch_level9:*:*:*:*:*:* cpe:2.3:a:sap:gui_for_windows:7.60:patch_level6:*:*:*:*:*:* cpe:2.3:a:sap:gui_for_windows:7.60:patch_level8:*:*:*:*:*:* cpe:2.3:a:sap:gui_for_windows:7.60:patch_level5:*:*:*:*:*:* cpe:2.3:a:sap:gui_for_windows:7.60:patch_level7:*:*:*:*:*:* cpe:2.3:a:sap:gui_for_windows:7.70:-:*:*:*:*:*:* cpe:2.3:a:sap:gui_for_windows:7.60:patch_level8_hotfix1:*:*:*:*:*:* |
16 Jun 2021, 12:15
Type | Values Removed | Values Added |
---|---|---|
Summary | In specific situations SAP GUI for Windows until and including 7.60 PL9, 7.70 PL0, forwards a user to specific malicious website which could contain malware or might lead to phishing attacks to steal credentials of the victim. |
10 Jun 2021, 11:15
Type | Values Removed | Values Added |
---|---|---|
Summary | In specific situations SAP GUI for Windows, versions - 7.60 PL10, 7.70 PL1, forwards a user to specific malicious website which could contain malware or might lead to phishing attacks to steal credentials of the victim. |
19 May 2021, 16:39
Type | Values Removed | Values Added |
---|---|---|
References | (MISC) https://launchpad.support.sap.com/#/notes/3023078 - Permissions Required, Vendor Advisory | |
References | (MISC) https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=576094655 - Vendor Advisory | |
CWE | CWE-601 | |
CVSS |
v2 : v3 : |
v2 : 5.8
v3 : 6.1 |
CPE | cpe:2.3:a:sap:gui_for_windows:7.70:*:*:*:*:*:*:* cpe:2.3:a:sap:gui_for_windows:7.60:*:*:*:*:*:*:* |
Information
Published : 2021-05-11 15:15
Updated : 2024-02-04 21:47
NVD link : CVE-2021-27612
Mitre link : CVE-2021-27612
CVE.ORG link : CVE-2021-27612
JSON object : View
Products Affected
sap
- gui_for_windows
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')