CVE-2015-8329
published 2015-11-24CVE-2015-8329: SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) uses weak encryption (Base64 and DES), which allows attackers to conduct downgrade…
PriorityP422medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
0.97%
57.7th percentile
SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) uses weak encryption (Base64 and DES), which allows attackers to conduct downgrade attacks and decrypt passwords via unspecified vectors, aka SAP Security Note 2240274.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sap | manufacturing_integration_and_intelligence | — | — |
| sap | manufacturing_integration_and_intelligence | — | — |
| sap | manufacturing_integration_and_intelligence | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/135761/SAP-MII-12.2-14.0-15.0-Cryptography-Issues.htmlhttp://seclists.org/fulldisclosure/2016/Feb/68https://erpscan.io/advisories/erpscan-15-031-using-base64-and-des-in-sap-mii/http://packetstormsecurity.com/files/135761/SAP-MII-12.2-14.0-15.0-Cryptography-Issues.htmlhttp://seclists.org/fulldisclosure/2016/Feb/68https://erpscan.io/advisories/erpscan-15-031-using-base64-and-des-in-sap-mii/
2015-11-24
Published