PT-2021-21984 · Sap · Sap Analysis For Microsoft Office
Published
2021-09-14
·
Updated
2021-09-24
·
CVE-2021-38175
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
SAP Analysis for Microsoft Office version 2.8
Description:
The issue allows an attacker with high privileges to read sensitive data over the network and gather or change information in the current system without user interaction. This would have an impact on the integrity and confidentiality of the system, but not on its availability.
Recommendations:
For SAP Analysis for Microsoft Office version 2.8, consider restricting access to sensitive data and implementing additional security measures to prevent unauthorized changes to the system until a fix is available. As a temporary workaround, limit the privileges of users who have access to the system to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap Analysis For Microsoft Office