Missing Authorization Check Vulnerability in SAP Host Agent 7.21
CVE-2020-6183
5.3MEDIUM
Summary
The SAP Host Agent version 7.21 is vulnerable to an issue that permits an unprivileged user to access shared memory. This can lead to unauthorized reading or writing of sensitive data by interacting with the main SAPOSCOL process. Attackers could exploit this vulnerability to retrieve critical system information, such as directory sizes and detailed hardware and operating system data, which should only be accessible with root privileges. Such exposure poses significant security risks to the integrity and confidentiality of the affected systems.
Affected Version(s)
SAP Host Agent = 7.21
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved