Advisory
A note with CVSS 5.0 for component BC-FES-GUI was released by SAP on 09.07.2024. The correction/advisory 3461110 was described with "[CVE-2024-39600] Information Disclosure vulnerability in SAP GUI for Windows" and affects the system type SAP GUI.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as monthly patch process.
The vulnerability addressed is insecure storage of sensitive data (password) within SAP GUI.
Risk specification
SAP GUI for Windows allows an authenticated attacker to access the process memory of SAP GUI for Windows and extract the password used to log on to the SAP system.Solution
An SAP GUI patch prevents the password from being extracted from the process memory.