Lucene search

K
cvelistSapCVELIST:CVE-2022-41209
HistoryOct 11, 2022 - 12:00 a.m.

CVE-2022-41209

2022-10-1100:00:00
CWE-326
sap
www.cve.org
sap
customer data cloud
gigya
mobile app
android
weak encryption
information disclosure
replay attacks

5.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

23.2%

SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses encryption method which lacks proper diffusion and does not hide the patterns well. This can lead to information disclosure. In certain scenarios, application might also be susceptible to replay attacks.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "SAP Customer Data Cloud (Gigya)",
    "vendor": "SAP SE",
    "versions": [
      {
        "status": "affected",
        "version": "7.4"
      }
    ]
  }
]

5.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

23.2%

Related for CVELIST:CVE-2022-41209