CVE-2016-3684

MEDIUM

SAP Download Manager <2.1.142 - Info Disclosure

Title source: llm

Description

SAP Download Manager 2.1.142 and earlier uses a hardcoded encryption key to protect stored data, which allows context-dependent attackers to obtain sensitive configuration information by leveraging knowledge of this key, aka SAP Security Note 2282338.

Scores

CVSS v3 4.7
EPSS 0.0007
EPSS Percentile 21.6%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

Status published

Affected Products (2)

n/a/n/a
sap/download_manager < 2.1.142

Timeline

Published Dec 14, 2016
Tracked Since Feb 18, 2026