First published: Tue Oct 11 2022(Updated: )
SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses insecure random number generator program which makes it easy for the attacker to predict future random numbers. This can lead to information disclosure and modification of certain user settings.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Customer Data Cloud | =7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-41210 is categorized as a medium severity vulnerability due to its potential to allow information disclosure and modification of user settings.
To fix CVE-2022-41210, upgrade to a more secure version of SAP Customer Data Cloud that addresses the insecure random number generator issue.
CVE-2022-41210 specifically affects SAP Customer Data Cloud version 7.4 for Android.
CVE-2022-41210 is a vulnerability related to the use of an insecure random number generator, which compromises the randomness of generated numbers.
Exploitation of CVE-2022-41210 can lead to information disclosure and unauthorized modification of user settings.