CVE-2024-47595

MEDIUM

SAP Host Agent - Incorrect Privilege Assignment

Title source: llm
STIX 2.1

Description

An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access. On successful exploitation the attacker could cause high impact on confidentiality and integrity of the application.

References (2)

Core 2
Core References
Permissions Required
https://me.sap.com/notes/3509619

Scores

CVSS v3 6.3
EPSS 0.0012
EPSS Percentile 30.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-266
Status published
Products (1)
sap/host_agent 7.22
Published Nov 12, 2024
Tracked Since Feb 18, 2026