« Volver al listado

CVE-2021-27612

Estado: ModificadaMedia (6.1)—

In specific situations SAP GUI for Windows until and including 7.60 PL9, 7.70 PL0, forwards a user to specific malicious website which could contain malware or might lead to phishing attacks to steal credentials of the victim.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2021-27612",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "cna@sap.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 3.4,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.6
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 6.1,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "cna@sap.com",
      "affectedData": [
        {
          "vendor": "SAP SE",
          "product": "SAP GUI for Windows",
          "versions": [
            {
              "status": "affected",
              "version": "< 7.60 PL10"
            },
            {
              "status": "affected",
              "version": "< 7.70 PL1"
            }
          ]
        }
      ]
    }
  ],
  "published": "2021-05-11T15:15:08.263",
  "references": [
    {
      "url": "https://launchpad.support.sap.com/#/notes/3023078",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=576094655",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cna@sap.com"
    },
    {
      "url": "https://launchpad.support.sap.com/#/notes/3023078",
      "tags": [
        "Permissions Required",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=576094655",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-601"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In specific situations SAP GUI for Windows until and including 7.60 PL9, 7.70 PL0, forwards a user to specific malicious website which could contain malware or might lead to phishing attacks to steal credentials of the victim."
    },
    {
      "lang": "es",
      "value": "En situaciones específicas, SAP GUI para Windows hasta e incluyendo las versiones 7.60 PL9, 7.70 PL0, reenvía a un usuario a un sitio web malicioso específico que podría contener malware o podría conllevar a ataques de phishing para robar las credenciales de la víctima"
    }
  ],
  "lastModified": "2026-06-17T03:45:13.790",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:7.60:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FA071418-F2F0-4530-94C0-94D9295FED83"
            },
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:7.60:patch_level1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E27CD53C-8CA1-4204-829D-3343AC4565B4"
            },
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:7.60:patch_level2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1E0246DF-E354-4191-91DA-99880E1BD08A"
            },
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:7.60:patch_level3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "140210E1-95C6-4EB5-A854-44E9EA03DD27"
            },
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:7.60:patch_level4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0FD672D2-D67A-4576-8F9B-92177AF51151"
            },
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:7.60:patch_level5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AE686D3C-E814-42D6-9F33-839763B53968"
            },
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:7.60:patch_level6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "711DE87F-72AA-4A6F-8F53-18758A195ED3"
            },
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:7.60:patch_level7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8E44C0EE-8ED0-42E8-81FB-7FE7FC9308E7"
            },
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:7.60:patch_level8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "98A928B5-F8AA-4CD0-A8A5-D4E04AB3856A"
            },
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:7.60:patch_level8_hotfix1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9415406D-32AF-41EB-A351-2DE0306657DB"
            },
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:7.60:patch_level9:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C7B83282-AD56-455F-9979-4F4D145F9798"
            },
            {
              "criteria": "cpe:2.3:a:sap:gui_for_windows:7.70:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "FE1286F1-B9A5-4F25-B083-272943D90023"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cna@sap.com"
}