First published: Thu Jul 16 2015(Updated: )
The Windows client in SAP Afaria 7.0.6398.0 uses weak permissions (Everyone: read and Everyone: write) for the install folder, which allows local users to gain privileges via a Trojan horse XeService.exe file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Afaria | =7.0.6398.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.