Description
- Credentials of logged in users are kept in memory for the duration of their session
- When user properties are read from MDM, passwords are kept in memory until the application is stopped
A malicious user who have operating system account to the GDS server with appropriate rights may steal credentials from the memory.
Available fix and Supported packages
- GDSCORE | 2.1 | 2.1
- GDSTOOLS | 2.1 | 2.1
- GDSUI | 2.1 | 2.1
- GDS CORE 2.1 | SP001 | 000013
- GDS UI 2.1 | SP001 | 000013
Affected component
- MDM-GDS
Global Data Synchronization
CVSS
Score: 0
PoC
Detailed vulnerability information added to RedRays Security Platform. Contact [email protected] for details.
URL
https://launchpad.support.sap.com/#/notes/1605531