CVE-2021-27612: Medium severity sap gui vulnerability
Published May 11, 2021
·Updated
In specific situations SAP GUI for Windows until and including 7.60 PL9, 7.70 PL0, forwards a user to specific malicious website which could contain malware or might lead to phishing attacks to steal credentials of the victim.
Affected Software
12 affected components
SAP GUI for Windows=7.60
SAP GUI for Windows=7.60-patch_level1
SAP GUI for Windows=7.60-patch_level2
SAP GUI for Windows=7.60-patch_level3
SAP GUI for Windows=7.60-patch_level4
SAP GUI for Windows=7.60-patch_level5
SAP GUI for Windows=7.60-patch_level6
SAP GUI for Windows=7.60-patch_level7
SAP GUI for Windows=7.60-patch_level8
SAP GUI for Windows=7.60-patch_level8_hotfix1
SAP GUI for Windows=7.60-patch_level9
SAP GUI for Windows=7.70
Event History
May 11, 2021
CVE Published
via MITRE·02:19 PM
Data Sourced
via MITRE·02:19 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-27612?
CVE-2021-27612 is considered a high-severity vulnerability due to its potential for leading users to malicious websites.
2
How do I fix CVE-2021-27612?
To fix CVE-2021-27612, update SAP GUI for Windows to version 7.60 PL10 or 7.70 PL1 or later.
3
What versions of SAP GUI for Windows are affected by CVE-2021-27612?
CVE-2021-27612 affects SAP GUI for Windows versions up to and including 7.60 PL9 and 7.70 PL0.
4
What type of attacks can CVE-2021-27612 enable?
CVE-2021-27612 can enable phishing attacks or delivery of malware by redirecting users to malicious websites.
5
Is there a workaround for CVE-2021-27612?
There are no recommended workarounds for CVE-2021-27612; users should upgrade to the latest versions.