SAP SAPCAR allows local users to change the permissions of arbitrary files and consequently gain privileges via a hard link attack on files extracted from an archive, possibly related to SAP Security Note 2327384.
References
Configurations
History
No history.
Information
Published : 2016-08-13 01:59
Updated : 2025-04-12 10:46
NVD link : CVE-2016-5847
Mitre link : CVE-2016-5847
CVE.ORG link : CVE-2016-5847
JSON object : View
Products Affected
sap
- sapcar_archive_tool
CWE
CWE-264
Permissions, Privileges, and Access Controls