CVE-2021-27612 (GCVE-0-2021-27612)
Vulnerability from cvelistv5
Published
2021-05-11 14:19
Modified
2024-08-03 21:26
CWE
  • URL Redirection to Untrusted Site
Summary
In specific situations SAP GUI for Windows until and including 7.60 PL9, 7.70 PL0, forwards a user to specific malicious website which could contain malware or might lead to phishing attacks to steal credentials of the victim.
Impacted products
Vendor Product Version
SAP SE SAP GUI for Windows Version: < 7.60 PL10
Version: < 7.70 PL1
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-03T21:26:10.276Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=576094655"
          },
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "https://launchpad.support.sap.com/#/notes/3023078"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "SAP GUI for Windows",
          "vendor": "SAP SE",
          "versions": [
            {
              "status": "affected",
              "version": "\u003c 7.60 PL10"
            },
            {
              "status": "affected",
              "version": "\u003c 7.70 PL1"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In specific situations SAP GUI for Windows until and including 7.60 PL9, 7.70 PL0, forwards a user to specific malicious website which could contain malware or might lead to phishing attacks to steal credentials of the victim."
        }
      ],
      "metrics": [
        {
          "cvssV3_0": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 3.4,
            "baseSeverity": "LOW",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "CHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N",
            "version": "3.0"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "URL Redirection to Untrusted Site",
              "lang": "en",
              "type": "text"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2021-06-16T11:39:18",
        "orgId": "e4686d1a-f260-4930-ac4c-2f5c992778dd",
        "shortName": "sap"
      },
      "references": [
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=576094655"
        },
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://launchpad.support.sap.com/#/notes/3023078"
        }
      ],
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "cna@sap.com",
          "ID": "CVE-2021-27612",
          "STATE": "PUBLIC"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "SAP GUI for Windows",
                      "version": {
                        "version_data": [
                          {
                            "version_name": "\u003c",
                            "version_value": "7.60 PL10"
                          },
                          {
                            "version_name": "\u003c",
                            "version_value": "7.70 PL1"
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "SAP SE"
              }
            ]
          }
        },
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "In specific situations SAP GUI for Windows until and including 7.60 PL9, 7.70 PL0, forwards a user to specific malicious website which could contain malware or might lead to phishing attacks to steal credentials of the victim."
            }
          ]
        },
        "impact": {
          "cvss": {
            "baseScore": "3.4",
            "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N",
            "version": "3.0"
          }
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "URL Redirection to Untrusted Site"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=576094655",
              "refsource": "MISC",
              "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=576094655"
            },
            {
              "name": "https://launchpad.support.sap.com/#/notes/3023078",
              "refsource": "MISC",
              "url": "https://launchpad.support.sap.com/#/notes/3023078"
            }
          ]
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "e4686d1a-f260-4930-ac4c-2f5c992778dd",
    "assignerShortName": "sap",
    "cveId": "CVE-2021-27612",
    "datePublished": "2021-05-11T14:19:33",
    "dateReserved": "2021-02-23T00:00:00",
    "dateUpdated": "2024-08-03T21:26:10.276Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1",
  "vulnerability-lookup:meta": {
    "nvd": "{\"cve\":{\"id\":\"CVE-2021-27612\",\"sourceIdentifier\":\"cna@sap.com\",\"published\":\"2021-05-11T15:15:08.263\",\"lastModified\":\"2024-11-21T05:58:17.800\",\"vulnStatus\":\"Modified\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"In specific situations SAP GUI for Windows until and including 7.60 PL9, 7.70 PL0, forwards a user to specific malicious website which could contain malware or might lead to phishing attacks to steal credentials of the victim.\"},{\"lang\":\"es\",\"value\":\"En situaciones espec\u00edficas, SAP GUI para Windows hasta e incluyendo las versiones 7.60 PL9, 7.70 PL0, reenv\u00eda a un usuario a un sitio web malicioso espec\u00edfico que podr\u00eda contener malware o podr\u00eda conllevar a ataques de phishing para robar las credenciales de la v\u00edctima\"}],\"metrics\":{\"cvssMetricV31\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"3.1\",\"vectorString\":\"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N\",\"baseScore\":6.1,\"baseSeverity\":\"MEDIUM\",\"attackVector\":\"NETWORK\",\"attackComplexity\":\"LOW\",\"privilegesRequired\":\"NONE\",\"userInteraction\":\"REQUIRED\",\"scope\":\"CHANGED\",\"confidentialityImpact\":\"LOW\",\"integrityImpact\":\"LOW\",\"availabilityImpact\":\"NONE\"},\"exploitabilityScore\":2.8,\"impactScore\":2.7}],\"cvssMetricV30\":[{\"source\":\"cna@sap.com\",\"type\":\"Secondary\",\"cvssData\":{\"version\":\"3.0\",\"vectorString\":\"CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N\",\"baseScore\":3.4,\"baseSeverity\":\"LOW\",\"attackVector\":\"NETWORK\",\"attackComplexity\":\"HIGH\",\"privilegesRequired\":\"NONE\",\"userInteraction\":\"REQUIRED\",\"scope\":\"CHANGED\",\"confidentialityImpact\":\"LOW\",\"integrityImpact\":\"NONE\",\"availabilityImpact\":\"NONE\"},\"exploitabilityScore\":1.6,\"impactScore\":1.4}],\"cvssMetricV2\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"2.0\",\"vectorString\":\"AV:N/AC:M/Au:N/C:P/I:P/A:N\",\"baseScore\":5.8,\"accessVector\":\"NETWORK\",\"accessComplexity\":\"MEDIUM\",\"authentication\":\"NONE\",\"confidentialityImpact\":\"PARTIAL\",\"integrityImpact\":\"PARTIAL\",\"availabilityImpact\":\"NONE\"},\"baseSeverity\":\"MEDIUM\",\"exploitabilityScore\":8.6,\"impactScore\":4.9,\"acInsufInfo\":false,\"obtainAllPrivilege\":false,\"obtainUserPrivilege\":false,\"obtainOtherPrivilege\":false,\"userInteractionRequired\":true}]},\"weaknesses\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"description\":[{\"lang\":\"en\",\"value\":\"CWE-601\"}]}],\"configurations\":[{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:sap:gui_for_windows:7.60:-:*:*:*:*:*:*\",\"matchCriteriaId\":\"FA071418-F2F0-4530-94C0-94D9295FED83\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:sap:gui_for_windows:7.60:patch_level1:*:*:*:*:*:*\",\"matchCriteriaId\":\"E27CD53C-8CA1-4204-829D-3343AC4565B4\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:sap:gui_for_windows:7.60:patch_level2:*:*:*:*:*:*\",\"matchCriteriaId\":\"1E0246DF-E354-4191-91DA-99880E1BD08A\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:sap:gui_for_windows:7.60:patch_level3:*:*:*:*:*:*\",\"matchCriteriaId\":\"140210E1-95C6-4EB5-A854-44E9EA03DD27\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:sap:gui_for_windows:7.60:patch_level4:*:*:*:*:*:*\",\"matchCriteriaId\":\"0FD672D2-D67A-4576-8F9B-92177AF51151\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:sap:gui_for_windows:7.60:patch_level5:*:*:*:*:*:*\",\"matchCriteriaId\":\"AE686D3C-E814-42D6-9F33-839763B53968\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:sap:gui_for_windows:7.60:patch_level6:*:*:*:*:*:*\",\"matchCriteriaId\":\"711DE87F-72AA-4A6F-8F53-18758A195ED3\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:sap:gui_for_windows:7.60:patch_level7:*:*:*:*:*:*\",\"matchCriteriaId\":\"8E44C0EE-8ED0-42E8-81FB-7FE7FC9308E7\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:sap:gui_for_windows:7.60:patch_level8:*:*:*:*:*:*\",\"matchCriteriaId\":\"98A928B5-F8AA-4CD0-A8A5-D4E04AB3856A\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:sap:gui_for_windows:7.60:patch_level8_hotfix1:*:*:*:*:*:*\",\"matchCriteriaId\":\"9415406D-32AF-41EB-A351-2DE0306657DB\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:sap:gui_for_windows:7.60:patch_level9:*:*:*:*:*:*\",\"matchCriteriaId\":\"C7B83282-AD56-455F-9979-4F4D145F9798\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:sap:gui_for_windows:7.70:-:*:*:*:*:*:*\",\"matchCriteriaId\":\"FE1286F1-B9A5-4F25-B083-272943D90023\"}]}]}],\"references\":[{\"url\":\"https://launchpad.support.sap.com/#/notes/3023078\",\"source\":\"cna@sap.com\",\"tags\":[\"Permissions Required\",\"Vendor Advisory\"]},{\"url\":\"https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=576094655\",\"source\":\"cna@sap.com\",\"tags\":[\"Vendor Advisory\"]},{\"url\":\"https://launchpad.support.sap.com/#/notes/3023078\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Permissions Required\",\"Vendor Advisory\"]},{\"url\":\"https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=576094655\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Vendor Advisory\"]}]}}"
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…