PT-2023-20651 · Sap+1 · Sap Landscape Management+2

Published

2023-04-11

·

Updated

2023-04-14

·

CVE-2023-26458

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions SAP Landscape Management version 3.0, enterprise edition
Description An information disclosure issue exists, allowing authenticated SAP Landscape Management users to obtain privileged access to other systems. This makes those systems vulnerable to information disclosure and modification. The disclosed information is related to Diagnostics Agent Connection via Java SCS Message Server of an SAP Solution Manager system. Authenticated SAP Landscape Management users can access this information and escalate their privileges to the SAP Solution Manager system.
Recommendations For SAP Landscape Management version 3.0, enterprise edition, consider restricting access to the Diagnostics Agent Connection via Java SCS Message Server to prevent privilege escalation until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-26458

Affected Products

Java
Sap Landscape Management
Sap Solution Manager