{"cve":{"cve_id":"CVE-2024-39600","is_kev":false,"kev_date_added":null,"kev_vendor_project":null,"kev_product":null,"kev_vulnerability_name":null,"kev_short_description":null,"kev_required_action":null,"kev_due_date":null,"kev_known_ransomware":null,"kev_notes":null,"kev_cwes":null,"epss_score":0.00148,"epss_percentile":0.04393,"epss_as_of":"2026-06-23","description":"Under certain conditions, the memory of SAP GUI\nfor Windows contains the password used to log on to an SAP system, which might\nallow an attacker to get hold of the password and impersonate the affected\nuser. As a result, it has a high impact on the confidentiality but there is no\nimpact on the integrity and availability.","published_at":"2024-07-09T04:19:47.498000Z","last_modified_at":null,"cvss_v3_score":5.0,"cvss_v3_vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:N/A:N","cvss_v3_severity":"MEDIUM","cvss_v4_score":null,"cvss_v4_vector":null,"cvss_v4_severity":null,"ssvc_decision":null,"ssvc_exploitation":"none","ssvc_automatable":false,"ssvc_technical_impact":"partial","cwes":["CWE-200"],"nvd_references":["https://url.sap/sapsecuritypatchday","https://me.sap.com/notes/3461110"],"vuln_status":null,"trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:39.878444Z","updated_at":"2026-06-29T02:02:46.435981Z"},"effective_severity":"MEDIUM","badges":[],"impact_analysis":[],"cvss_v3_decoded":{"version":"3.1","metrics":[{"metric":"AV","name":"Attack Vector","value":"L","value_label":"Local"},{"metric":"AC","name":"Attack Complexity","value":"H","value_label":"High"},{"metric":"PR","name":"Privileges Required","value":"H","value_label":"High"},{"metric":"UI","name":"User Interaction","value":"R","value_label":"Required"},{"metric":"S","name":"Scope","value":"C","value_label":"Changed"},{"metric":"C","name":"Confidentiality","value":"H","value_label":"High"},{"metric":"I","name":"Integrity","value":"N","value_label":"None"},{"metric":"A","name":"Availability","value":"N","value_label":"None"}]},"cvss_v4_decoded":{"version":null,"metrics":[]},"affected":[{"vendor_slug":"sap-se","vendor_name":"SAP_SE","product_slug":"sap-gui-for-windows","product_name":"SAP GUI for Windows","version_start":"BC-FES-GUI 8","version_start_inclusive":true,"version_end":"BC-FES-GUI 8","version_end_inclusive":true,"cpe23_uri":"cve5:sap-se:sap-gui-for-windows:BC-FES-GUI 8:BC-FES-GUI 8"}],"exploit_refs":[],"news":[],"references":[{"url":"https://url.sap/sapsecuritypatchday","source_type":"MISC","tags":["patch"]},{"url":"https://me.sap.com/notes/3461110","source_type":"MISC","tags":[]}],"timeline":[{"type":"published","at":"2024-07-09T04:19:47.498000Z","label":"CVE published","source":null},{"type":"cvss_changed","at":"2026-06-28T17:36:45.073514Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:36:45.073514Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:36:45.073514Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"ssvc_changed","at":"2026-06-29T02:02:46.435981Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-29T02:02:46.435981Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-29T02:02:46.435981Z","label":"SSVC decision revised","source":"vulnrichment"}]}