Description
The Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any authentication checks for functionalities that can be accessed via localhost on http port 3005. Due to lack of authentication checks, an attacker could access administrative or other privileged functionalities and read, modify, or delete sensitive information and configurations.
References (4)
Core 4
Core References
Vendor Advisory x_refsource_misc
https://dam.sap.com/mac/embed/public/pdf/a/ucQrx6G.htm?rc=10
Permissions Required, Vendor Advisory x_refsource_misc
https://launchpad.support.sap.com/#/notes/3145987
Exploit, Mailing List, Third Party Advisory mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2022/Jun/38
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/167560/SAP-FRUN-Simple-Diagnostics-Agent-1.0-Missing-Authentication.html
Scores
CVSS v3
7.8
EPSS
0.0018
EPSS Percentile
39.8%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-306
Status
published
Products (1)
sap/simple_diagnostics_agent
1.0 - 1.57
Published
Mar 10, 2022
Tracked Since
Feb 18, 2026