PT-2023-19671 · Sap · Sap Host Agent

Published

2023-02-14

·

Updated

2024-02-01

·

CVE-2023-24523

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SAP Host Agent (Start Service) versions 7.21, 7.22
Description An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent can submit a crafted ConfigureOutsideDiscovery request with an operating system command which will be executed with administrator privileges. The OS command can read or modify any user or system data and can make the system unavailable.
Recommendations For versions 7.21 and 7.22, consider disabling the ConfigureOutsideDiscovery request functionality until a patch is available to prevent potential exploitation. Restrict access to the server port assigned to the SAP Host Agent to minimize the risk of unauthorized access.

Fix

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2023-24523

Affected Products

Sap Host Agent