Memory Corruption vulnerability in SAP Host Agent (SAPOSCOL)
CVE-2023-27498

7.2HIGH

Key Information:

Vendor
SAP
Vendor
CVE Published:
14 March 2023

Summary

The SAP Host Agent (SAPOSCOL) version 7.22 is susceptible to a memory corruption issue that allows unauthenticated attackers with network access to exploit a server port assigned to the SAP Start Service. By submitting a specially crafted request, attackers can trigger a memory corruption error. This vulnerability can potentially expose technical information about the server without the ability to modify it, and it may lead to temporary service disruptions.

Affected Version(s)

Host Agent (SAPOSCOL) 7.22

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.