PT-2023-19671 · Sap · Sap Host Agent

CVE-2023-24523

·

Publicado

2023-02-14

·

Atualizado

2024-02-01

CVSS v3.1

8.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP Host Agent (Start Service) versions 7.21, 7.22
Description An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent can submit a crafted ConfigureOutsideDiscovery request with an operating system command which will be executed with administrator privileges. The OS command can read or modify any user or system data and can make the system unavailable.
Recommendations For versions 7.21 and 7.22, consider disabling the ConfigureOutsideDiscovery request functionality until a patch is available to prevent potential exploitation. Restrict access to the server port assigned to the SAP Host Agent to minimize the risk of unauthorized access.

Correção

Exposure of Resource to Wrong Sphere

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-24523

Produtos afetados

Sap Host Agent