First published: Tue Oct 11 2022(Updated: )
SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses encryption method which lacks proper diffusion and does not hide the patterns well. This can lead to information disclosure. In certain scenarios, application might also be susceptible to replay attacks.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Customer Data Cloud | =7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41209 has a moderate severity rating due to potential information disclosure and susceptibility to replay attacks.
To address CVE-2022-41209, upgrade SAP Customer Data Cloud to a version that implements stronger encryption methods.
The main risks include information disclosure and the possibility of replay attacks due to insufficient encryption diffusion.
Yes, CVE-2022-41209 specifically affects the Android version of SAP Customer Data Cloud, version 7.4.
Yes, CVE-2022-41209 can potentially expose user data through information disclosure vulnerabilities.