CVE-2023-24523
Last modified
CVE-2023-24523 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent (Start Service) - versions 7.21, 7.22, can submit a crafted ConfigureOutsideDiscovery request with an operating system command which will be executed with administrator privileges. The OS command can read or modify any user or system data and can make the system unavailable. . EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent (Start Service) - versions 7.21, 7.22, can submit a crafted ConfigureOutsideDiscovery request with an operating system command which will be executed with administrator privileges. The OS command can read or modify any user or system data and can make the system unavailable.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Host Agent | 7.21 |
| Sap | Host Agent | 7.22 |
References
- https://launchpad.support.sap.com/#/notes/3285757Permissions Required, Vendor Advisory
- https://launchpad.support.sap.com/#/notes/3285757Permissions Required, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-24523?
How severe is CVE-2023-24523?
How do I fix CVE-2023-24523?
Are you affected by CVE-2023-24523?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
