PT-2023-4215 · Sap · Sap Host Agent
CVE-2023-36926
·
Publicado
2023-08-08
·
Atualizado
2024-09-26
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SAP Host Agent version 7.22
Description
The issue is related to a missing authentication check in the SAP Host Agent, allowing an unauthenticated attacker to set an undocumented parameter to a particular compatibility value. This enables the attacker to call read functions and gather some non-sensitive information about the server. There is no impact on the server's integrity or availability.
Recommendations
For SAP Host Agent version 7.22, consider implementing additional authentication checks to prevent unauthorized access until a patch is available. As a temporary workaround, restrict access to the read functions to minimize the risk of exploitation.
Correção
Missing Authentication
Improper Authentication
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sap Host Agent