Description
SAP Process Integration (PGP Module - Business-to-Business Add On), version - 1.0, allows an attacker to read PGP Keys under certain conditions in the PGP Module of Business-to-Business Add-On, these keys can then be used to read messages processed by the module leading to Information Disclosure.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_misc
https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=562725571
Permissions Required x_refsource_misc
https://launchpad.support.sap.com/#/notes/2952084
Scores
CVSS v3
4.9
EPSS
0.0024
EPSS Percentile
46.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Details
Status
published
Products (1)
sap/process_integration_\(pgp_module_-_business-to-business_add_on\)
1.0
Published
Nov 10, 2020
Tracked Since
Feb 18, 2026