CVE-2024-47595

An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access. On successful exploitation the attacker could cause high impact on confidentiality and integrity of the application.
References
Link Resource
https://me.sap.com/notes/3509619 Permissions Required
https://url.sap/sapsecuritypatchday Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:sap:host_agent:7.22:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-11-12 01:15

Updated : 2024-11-14 15:21


NVD link : CVE-2024-47595

Mitre link : CVE-2024-47595

CVE.ORG link : CVE-2024-47595


JSON object : View

Products Affected

sap

  • host_agent
CWE
CWE-266

Incorrect Privilege Assignment

NVD-CWE-noinfo