PT-2023-21402 · Sap · Sap Authenticator For Android

Published

2023-03-14

·

Updated

2023-04-11

·

CVE-2023-27895

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP Authenticator for Android version 1.3.0
Description The issue allows an authorized attacker to capture the screen if a malicious app is installed on the mobile device. This could lead to the extraction of the currently viewed OTP and the secret OTP alphanumeric token during token setup. On successful exploitation, an attacker can read some sensitive information but cannot modify or delete the data.
Recommendations For SAP Authenticator for Android version 1.3.0, consider restricting access to sensitive information until a patch is available. As a temporary workaround, avoid using the app for token setup until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2023-27895

Affected Products

Sap Authenticator For Android