PT-2023-4215 · Sap · Sap Host Agent

CVE-2023-36926

·

Publicado

2023-08-08

·

Atualizado

2024-09-26

CVSS v3.1

5.3

Média

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP Host Agent version 7.22
Description The issue is related to a missing authentication check in the SAP Host Agent, allowing an unauthenticated attacker to set an undocumented parameter to a particular compatibility value. This enables the attacker to call read functions and gather some non-sensitive information about the server. There is no impact on the server's integrity or availability.
Recommendations For SAP Host Agent version 7.22, consider implementing additional authentication checks to prevent unauthorized access until a patch is available. As a temporary workaround, restrict access to the read functions to minimize the risk of exploitation.

Correção

Missing Authentication

Improper Authentication

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-04530
CVE-2023-36926

Produtos afetados

Sap Host Agent