PT-2022-6152 · Sap · Sap Customer Data Cloud
Published
2022-10-11
·
Updated
2022-10-12
·
CVE-2022-41209
CVSS v2.0
5.6
Medium
| Vector | AV:L/AC:L/Au:N/C:C/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
SAP Customer Data Cloud (Gigya mobile app for Android) version 7.4
Description
The issue is related to an insufficiently robust encryption method used by the software, which lacks proper diffusion and does not effectively hide patterns. This can lead to information disclosure. In certain scenarios, the application may also be susceptible to replay attacks. The vulnerability can be exploited by a remote attacker to disclose protected information.
Recommendations
For version 7.4, consider updating the encryption method to one that provides proper diffusion and effectively hides patterns to prevent information disclosure and replay attacks. As a temporary workaround, restrict access to sensitive data handled by the application to minimize the risk of exploitation.
Fix
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Customer Data Cloud