CVE-2022-41210

medium

Description

SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses insecure random number generator program which makes it easy for the attacker to predict future random numbers. This can lead to information disclosure and modification of certain user settings.

References

https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html

https://launchpad.support.sap.com/#/notes/3248384

Details

Source: Mitre, NVD

Published: 2022-10-11

Updated: 2026-06-17

Risk Information

CVSS v2

Base Score: 5.6

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 5.2

Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.00152