menu
techminis

A naukri.com initiative

google-web-stories
Home

>

Technology News

>

Researcher...
source image

Siliconangle

8h

read

141

img
dot

Image Credit: Siliconangle

Researchers uncover weak encryption in SAP user interface for Windows and Java

  • SAP addressed vulnerabilities in its SAP GUI client applications, discovered by Pathlock Inc. and Fortinet Inc., involving weak or absent encryption in input history functions.
  • The vulnerabilities, CVE-2025-0055 and CVE-2025-0056, exposed sensitive user data stored on local machines due to encryption issues in SAP GUI for Windows and SAP GUI for Java.
  • SAP GUI for Windows stored data using weak XOR-based encryption, making it easily reversible, while SAP GUI for Java stored data entirely unencrypted in serialized objects.
  • SAP released updates to address the vulnerabilities but experts recommend disabling input history feature and implementing mitigation measures due to the potential risk of exposure of sensitive data.

Read Full Article

like

8 Likes

For uninterrupted reading, download the app