CVE-2024-47595
Last modified
CVE-2024-47595 is a high-severity vulnerability rated 7.1/10 on the CVSS scale. An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access. On successful exploitation the attacker could cause high impact on confidentiality and integrity of the application.. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access. On successful exploitation the attacker could cause high impact on confidentiality and integrity of the application.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Sap | Host Agent | 7.22 |
References
- https://me.sap.com/notes/3509619Permissions Required
- https://url.sap/sapsecuritypatchdayVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-47595?
How severe is CVE-2024-47595?
How do I fix CVE-2024-47595?
Are you affected by CVE-2024-47595?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
