CVE-2021-38175 Information
Jun 07, 2022
cve
Description
SAP Analysis for Microsoft Office - version 2.8 allows an attacker with high privileges to read sensitive data over the network and gather or change information in the current system without user interaction. The attack would not lead to an impact on the availability of the system but there would be an impact on integrity and confidentiality.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Reference
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=585106405 https://launchpad.support.sap.com/#/notes/3082500
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction Required
HIGH
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
NONE
Base Severity
6.5
Share on: