PT-2023-19671 · Sap · Sap Host Agent
Published
2023-02-14
·
Updated
2024-02-01
·
CVE-2023-24523
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SAP Host Agent (Start Service) versions 7.21, 7.22
Description
An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent can submit a crafted ConfigureOutsideDiscovery request with an operating system command which will be executed with administrator privileges. The OS command can read or modify any user or system data and can make the system unavailable.
Recommendations
For versions 7.21 and 7.22, consider disabling the ConfigureOutsideDiscovery request functionality until a patch is available to prevent potential exploitation. Restrict access to the server port assigned to the SAP Host Agent to minimize the risk of unauthorized access.
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sap Host Agent