Privilege Escalation Vulnerability in SAPCAR by SAP
CVE-2016-5847

5.8MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
13 August 2016

Summary

The SAPCAR tool, utilized in SAP environments, is susceptible to a privilege escalation flaw that allows local users to manipulate file permissions. By exploiting hard link tactics when extracting files from an archive, attackers can gain elevated privileges, potentially compromising system security. This vulnerability underscores the importance of strict access controls and file integrity checks within SAP systems.

References

CVSS V3.1

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.