Local Privilege Escalation in SAP PowerDesigner Proxy by SAP
CVE-2022-31590

7.8HIGH

Key Information:

Vendor
SAP
Vendor
CVE Published:
14 June 2022

Summary

SAP PowerDesigner Proxy version 16.7 is susceptible to a local privilege escalation vulnerability that allows an attacker with low privileges and local access to bypass system's root disk access restrictions. By writing or creating a program file in the system disk root path, the attacker could execute this file with elevated application privileges at startup or upon rebooting the system. This could lead to severe compromises in the confidentiality, integrity, and availability of the affected system.

Affected Version(s)

SAP PowerDesigner Proxy 16.7 16.7

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.