PT-2022-6152 · Sap · Sap Customer Data Cloud

Published

2022-10-11

·

Updated

2022-10-12

·

CVE-2022-41209

CVSS v2.0

5.6

Medium

VectorAV:L/AC:L/Au:N/C:C/I:P/A:N
Name of the Vulnerable Software and Affected Versions SAP Customer Data Cloud (Gigya mobile app for Android) version 7.4
Description The issue is related to an insufficiently robust encryption method used by the software, which lacks proper diffusion and does not effectively hide patterns. This can lead to information disclosure. In certain scenarios, the application may also be susceptible to replay attacks. The vulnerability can be exploited by a remote attacker to disclose protected information.
Recommendations For version 7.4, consider updating the encryption method to one that provides proper diffusion and effectively hides patterns to prevent information disclosure and replay attacks. As a temporary workaround, restrict access to sensitive data handled by the application to minimize the risk of exploitation.

Fix

Inadequate Encryption Strength

Weakness Enumeration

Related Identifiers

BDU:2023-00226
CVE-2022-41209

Affected Products

Sap Customer Data Cloud