Due to missing authentication check in SAP Host Agent -...
Moderate severity
Unreviewed
Published
Aug 8, 2023
to the GitHub Advisory Database
•
Updated Sep 26, 2024
Description
Published by the National Vulnerability Database
Aug 8, 2023
Published to the GitHub Advisory Database
Aug 8, 2023
Last updated
Sep 26, 2024
Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumented parameter to a particular compatibility value and in turn call read functions. This allows the attacker to gather some non-sensitive information about the server. There is no impact on integrity or availability.
References