Attacker Could Replace Local Files, Causing High Impact on Confidentiality and Integrity
CVE-2024-47595

7.1HIGH

Key Information:

Vendor
SAP
Vendor
CVE Published:
12 November 2024

Summary

A local file replacement vulnerability exists within SAP systems, where an attacker with membership in the sapsys group can exploit this weakness to replace files normally protected by higher privilege levels. This exploitation can significantly undermine the confidentiality and integrity of the affected applications, leading to unauthorized access and modifications to sensitive data. Organizations using SAP applications should be vigilant and apply necessary security patches to mitigate potential risks associated with this vulnerability.

Affected Version(s)

SAP Host Agent SAPHOSTAGENT 7.22

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.