PT-2020-4202 · Sap · Sap Host Agent
Published
2020-04-14
·
Updated
2022-04-29
·
CVE-2020-6234
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
SAP Host Agent version 7.21
Description:
The issue is related to insufficient access control in the SAP Host Agent, allowing a remote attacker to escalate privileges to the root level. This can be achieved by an attacker with admin privileges using the operation framework to gain root privileges over the underlying operating system.
Recommendations:
For SAP Host Agent version 7.21, consider restricting access to the operation framework to prevent privilege escalation until a patch is available. As a temporary workaround, limit the use of admin privileges to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Host Agent