CVE-2016-3946

HIGH

SAP Console <7.30 - Info Disclosure

Title source: llm
STIX 2.1

Description

SAP Console (aka SAPConsole) 7.30 allows local users to discover SAP Server login credentials by reading the Windows registry, aka SAP Security Note 2121461.

References (3)

Core 3
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2016/Oct/31
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/93509

Scores

CVSS v3 7.8
EPSS 0.0005
EPSS Percentile 17.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-200 CWE-255
Status published
Products (1)
sap/sapconsole 7.30
Published Oct 13, 2016
Tracked Since Feb 18, 2026