Missing Authorization Check Vulnerability in SAP Host Agent 7.21
CVE-2020-6183

5.3MEDIUM

Key Information:

Vendor
SAP
Vendor
CVE Published:
12 February 2020

Summary

The SAP Host Agent version 7.21 is vulnerable to an issue that permits an unprivileged user to access shared memory. This can lead to unauthorized reading or writing of sensitive data by interacting with the main SAPOSCOL process. Attackers could exploit this vulnerability to retrieve critical system information, such as directory sizes and detailed hardware and operating system data, which should only be accessible with root privileges. Such exposure poses significant security risks to the integrity and confidentiality of the affected systems.

Affected Version(s)

SAP Host Agent = 7.21

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.