CVE-2022-41210
CVE-2022-41210 is a medium-severity vulnerability in Sap Customer Data Cloud with a CVSS 3.x base score of 5.2. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-338.
Key facts
- Severity: Medium (CVSS 3.x base score 5.2)
- EPSS exploit prediction: 0% (33rd percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-338
- Affected product: Sap Customer Data Cloud
- Published:
- Last modified:
Description
SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses insecure random number generator program which makes it easy for the attacker to predict future random numbers. This can lead to information disclosure and modification of certain user settings.
Frequently asked questions
- What is CVE-2022-41210?
- SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses insecure random number generator program which makes it easy for the attacker to predict future random numbers. This can lead to information disclosure and modification of certain user settings.
- How severe is CVE-2022-41210?
- CVE-2022-41210 has a CVSS 3.x base score of 5.2, rated medium severity. It is exploitable over physical access with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity low, and availability none.
- Is CVE-2022-41210 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (33rd percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2022-41210?
- CVE-2022-41210 affects Sap Customer Data Cloud. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2022-41210?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2022-41210 published?
- CVE-2022-41210 was published on 2022-10-11 and last updated on 2026-06-17.
References
- https://launchpad.support.sap.com/#/notes/3248384
- https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html
Affected products (1)
- cpe:2.3:a:sap:customer_data_cloud:7.4:*:*:*:*:android:*:*
More vulnerabilities in Sap Customer Data Cloud
- CVE-2022-41209 — Medium (CVSS 5.2): SAP Customer Data Cloud (Gigya mobile app for Android) - version 7.4, uses encryption method which lacks proper…
All CVEs affecting Sap Customer Data Cloud →
Other CWE-338 vulnerabilities
- CVE-2026-16235 — Critical (CVSS 9.8): Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the…
- CVE-2026-61500 — Critical (CVSS 9.8): Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random()…
- CVE-2026-56141 — Critical (CVSS 9.8): In JetBrains Hub before 2026.1.13757, 2025.3.148033, 2025.2.148048, 2025.1.148120, 2024.3.148430, 2024.2.148429 account…
- CVE-2026-3256 — Critical (CVSS 9.8): HTTP::Session versions before 0.54 for Perl defaults to using insecurely generated session ids. HTTP::Session defaults…
- CVE-2025-15604 — Critical (CVSS 9.8): Amon2 versions before 6.17 for Perl use an insecure random_string implementation for security functions. In versions…
- CVE-2025-40926 — Critical (CVSS 9.8): Plack::Middleware::Session::Simple versions before 0.05 for Perl generates session ids insecurely. The default session…