CVE-2015-8329
Estado: ModificadaMedia (5)—
SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) uses weak encryption (Base64 and DES), which allows attackers to conduct downgrade attacks and decrypt passwords via unspecified vectors, aka SAP Security Note 2240274.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
- Puntuación base: 5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.97%
- Percentil entre todas las CVEs puntuadas: 61
- Fecha de la puntuación: 3/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-310
Referencias
- http://packetstormsecurity.com/files/135761/SAP-MII-12.2-14.0-15.0-Cryptography-Issues.html
- http://seclists.org/fulldisclosure/2016/Feb/68
- https://erpscan.io/advisories/erpscan-15-031-using-base64-and-des-in-sap-mii/
- http://packetstormsecurity.com/files/135761/SAP-MII-12.2-14.0-15.0-Cryptography-Issues.html
- http://seclists.org/fulldisclosure/2016/Feb/68
- https://erpscan.io/advisories/erpscan-15-031-using-base64-and-des-in-sap-mii/
JSON original (NVD)
Mostrar
{
"id": "CVE-2015-8329",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": true,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2015-11-24T20:59:24.757",
"references": [
{
"url": "http://packetstormsecurity.com/files/135761/SAP-MII-12.2-14.0-15.0-Cryptography-Issues.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "cve@mitre.org"
},
{
"url": "http://seclists.org/fulldisclosure/2016/Feb/68",
"source": "cve@mitre.org"
},
{
"url": "https://erpscan.io/advisories/erpscan-15-031-using-base64-and-des-in-sap-mii/",
"source": "cve@mitre.org"
},
{
"url": "http://packetstormsecurity.com/files/135761/SAP-MII-12.2-14.0-15.0-Cryptography-Issues.html",
"tags": [
"Third Party Advisory",
"VDB Entry"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://seclists.org/fulldisclosure/2016/Feb/68",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://erpscan.io/advisories/erpscan-15-031-using-base64-and-des-in-sap-mii/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-310"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) uses weak encryption (Base64 and DES), which allows attackers to conduct downgrade attacks and decrypt passwords via unspecified vectors, aka SAP Security Note 2240274."
},
{
"lang": "es",
"value": "SAP Manufacturing Integration and Intelligence (también conocida como MII, anteriormente xMII), utiliza un cifrado débil (Base64 y DES),lo que permite a atacantes llevar a cabo ataques de bajada de versión y descifrar contraseñas a través de vectores no especificados, también conocida como SAP Security Note 2240274."
}
],
"lastModified": "2026-06-17T00:34:19.923",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:sap:manufacturing_integration_and_intelligence:12.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1273F8D1-D4F4-4D73-B068-FC83053D1436"
},
{
"criteria": "cpe:2.3:a:sap:manufacturing_integration_and_intelligence:14.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ADCD48D2-4E00-4544-8846-DC45AD748342"
},
{
"criteria": "cpe:2.3:a:sap:manufacturing_integration_and_intelligence:15.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E49597EA-582C-4F2C-8D30-760620BA9FA6"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}