Description
Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumented parameter to a particular compatibility value and in turn call read functions. This allows the attacker to gather some non-sensitive information about the server. There is no impact on integrity or availability.
References (2)
Core 2
Core References
Permissions Required
https://me.sap.com/notes/3358328
Scores
CVSS v3
3.7
EPSS
0.0036
EPSS Percentile
58.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-287
CWE-306
Status
published
Products (1)
sap/host_agent
7.22
Published
Aug 08, 2023
Tracked Since
Feb 18, 2026