CVE-2021-38175

SAP Analysis for Microsoft Office - version 2.8, allows an attacker with high privileges to read sensitive data over the network, and gather or change information in the current system without user interaction. The attack would not lead to an impact on the availability of the system, but there would be an impact on integrity and confidentiality.
Configurations

Configuration 1 (hide)

cpe:2.3:a:sap:analysis_for_microsoft_office:2.8:*:*:*:*:*:*:*

History

21 Nov 2024, 06:16

Type Values Removed Values Added
References () https://launchpad.support.sap.com/#/notes/3082500 - Permissions Required () https://launchpad.support.sap.com/#/notes/3082500 - Permissions Required
References () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405 - Vendor Advisory () https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405 - Vendor Advisory

24 Sep 2021, 16:17

Type Values Removed Values Added
CWE CWE-200
References (MISC) https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405 - (MISC) https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405 - Vendor Advisory
References (MISC) https://launchpad.support.sap.com/#/notes/3082500 - (MISC) https://launchpad.support.sap.com/#/notes/3082500 - Permissions Required
CPE cpe:2.3:a:sap:analysis_for_microsoft_office:2.8:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 5.5
v3 : 6.5

14 Sep 2021, 13:01

Type Values Removed Values Added
New CVE

Information

Published : 2021-09-14 12:15

Updated : 2024-11-21 06:16


NVD link : CVE-2021-38175

Mitre link : CVE-2021-38175

CVE.ORG link : CVE-2021-38175


JSON object : View

Products Affected

sap

  • analysis_for_microsoft_office