CVE-2023-27895
CVSS V2 None
CVSS V3 None
Description
SAP Authenticator for Android - version 1.3.0, allows the screen to be captured, if an authorized attacker installs a malicious app on the mobile device. The attacker could extract the currently views of the OTP and the secret OTP alphanumeric token during the token setup. On successful exploitation, an attacker can read some sensitive information but cannot modify and delete the data.
Overview
- CVE ID
- CVE-2023-27895
- Assigner
- cna@sap.com
- Vulnerability Status
- Modified
- Published Version
- 2023-03-14T06:15:12
- Last Modified Date
- 2023-04-11T04:16:06
Weakness Enumerations
CPE Configuration (Product)
CPE | Vulnerable | Operator | Version Start | Version End |
---|---|---|---|---|
cpe:2.3:a:sap:authenticator:1.3.0:*:*:*:*:android:*:* | 1 | OR |
References
Reference URL | Reference Tags |
---|---|
https://launchpad.support.sap.com/#/notes/3302710 | Permissions Required |
https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html | Vendor Advisory |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-27895 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-27895 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2023-04-17 06:23:34 | Added to TrackCVE | |||
2023-04-17 06:23:36 | Weakness Enumeration | new |