VulnerabilityModified
CVE-2015-7731
SAP Mobile Platform 3.0 SP05 ClientHub allows attackers to obtain the keystream and other sensitive information via the DataVault, aka SAP Security Note 2094830.
MEDIUM 5.5EPSS 0.25%
Does this matter?
Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.
Description
SAP Mobile Platform 3.0 SP05 ClientHub allows attackers to obtain the keystream and other sensitive information via the DataVault, aka SAP Security Note 2094830.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.25% probability · 16th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- sap/mobile platform
- Source
- cve@mitre.org
References
- https://seclists.org/bugtraq/2015/Aug/39Mailing List, Third Party Advisory
- https://www.onapsis.com/research/security-advisories/SAP-Mobile-Platform-DataVault-Keystream-RecoveryProduct
- https://seclists.org/bugtraq/2015/Aug/39Mailing List, Third Party Advisory
- https://www.onapsis.com/research/security-advisories/SAP-Mobile-Platform-DataVault-Keystream-RecoveryProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.