SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-37484

SAP PowerDesigner - version 16.7, queries all password hashes in the backend database and compares it with the user provided one during login attempt, which might allow an attacker to access password hashes from the client's memory.

MEDIUM 5.3EPSS 1.98%

Does this matter?

Lower severity and a low EPSS score (1.98%). Track it; it rarely justifies an emergency change on its own.

Description

SAP PowerDesigner - version 16.7, queries all password hashes in the backend database and compares it with the user provided one during login attempt, which might allow an attacker to access password hashes from the client's memory.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
1.98% probability · 79th percentile
CISA KEV
Not listed
Weakness
CWE-327
Affected
sap/powerdesigner
Source
cna@sap.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.