CVE-2022-41210
low-risk
Published 2022-10-11
SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses insecure random number generator program which makes it easy for the attacker to predict future random numbers. This can lead to information disclosure and modification of certain user settings.
Do I need to act?
-
0.08% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.2/10
Medium
PHYSICAL
/ LOW complexity
Affected Products (1)
Customer Data Cloud
Affected Vendors
References (4)
Permissions Required
https://launchpad.support.sap.com/#/notes/3248384
Permissions Required
https://launchpad.support.sap.com/#/notes/3248384
23
/ 100
low-risk
Severity
18/34 · Moderate
Exploitability
0/34 · Minimal
Exposure
5/34 · Minimal