PT-2022-6135 · Microsoft+1 · Windows+1
Published
2022-12-12
·
Updated
2023-07-10
·
CVE-2022-41261
CVSS v3.1
6.0
Medium
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SAP Solution Manager (Diagnostic Agent) version 7.20
Description
The issue allows an authenticated attacker on a Windows system to access a file containing sensitive data, which can be used to access a configuration file containing credentials to access other system files. Successful exploitation can grant the attacker access to files and systems for which they are not authorized. The vulnerability is related to insufficient access control in the Diagnostic Agent tool of the SAP Solution Manager platform.
Recommendations
For SAP Solution Manager (Diagnostic Agent) version 7.20, consider restricting access to sensitive files and configuration files as a temporary workaround until a patch is available. Additionally, review and enforce strict access controls to prevent unauthorized access to system files and credentials. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Solution Manager
Windows