PT-2023-4215 · Sap · Sap Host Agent

Published

2023-08-08

·

Updated

2024-09-26

·

CVE-2023-36926

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions SAP Host Agent version 7.22
Description The issue is related to a missing authentication check in the SAP Host Agent, allowing an unauthenticated attacker to set an undocumented parameter to a particular compatibility value. This enables the attacker to call read functions and gather some non-sensitive information about the server. There is no impact on the server's integrity or availability.
Recommendations For SAP Host Agent version 7.22, consider implementing additional authentication checks to prevent unauthorized access until a patch is available. As a temporary workaround, restrict access to the read functions to minimize the risk of exploitation.

Fix

Missing Authentication

Improper Authentication

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2023-04530
CVE-2023-36926

Affected Products

Sap Host Agent