Vulnerability Details CVE-2016-3685
SAP Download Manager 2.1.142 and earlier generates an encryption key from a small key space on Windows and Mac systems, which allows context-dependent attackers to obtain sensitive configuration information by leveraging knowledge of a hardcoded key in the program code and a computer BIOS serial number, aka SAP Security Note 2282338.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 15.9%
CVSS Severity
CVSS v3 Score 4.7
CVSS v2 Score 1.9
Products affected by CVE-2016-3685
-
cpe:2.3:a:sap:download_manager:1.1.3.0
-
cpe:2.3:a:sap:download_manager:2.1.142
-
-
cpe:2.3:o:microsoft:windows:-