PT-2020-4202 · Sap · Sap Host Agent

Published

2020-04-14

·

Updated

2022-04-29

·

CVE-2020-6234

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: SAP Host Agent version 7.21
Description: The issue is related to insufficient access control in the SAP Host Agent, allowing a remote attacker to escalate privileges to the root level. This can be achieved by an attacker with admin privileges using the operation framework to gain root privileges over the underlying operating system.
Recommendations: For SAP Host Agent version 7.21, consider restricting access to the operation framework to prevent privilege escalation until a patch is available. As a temporary workaround, limit the use of admin privileges to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04636
CVE-2020-6234

Affected Products

Sap Host Agent