CVE-2017-15297: High severity sap host agent vulnerability
Published Oct 16, 2017
·Updated
SAP Hostcontrol does not require authentication for the SOAP SAPControl endpoint. This is SAP Security Note 2442993.
Affected Software
1 affected component
SAP Host Agent Hostcontrol=7.21
Event History
Oct 16, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-15297?
CVE-2017-15297 has a critical severity due to the lack of authentication for the SOAP SAPControl endpoint.
2
How do I fix CVE-2017-15297?
To fix CVE-2017-15297, ensure that authentication is required for the SOAP SAPControl endpoint as described in SAP Security Note 2442993.
3
What systems are affected by CVE-2017-15297?
CVE-2017-15297 affects the SAP Host Agent version 7.21.
4
What type of vulnerability is CVE-2017-15297?
CVE-2017-15297 is an authentication vulnerability that allows unauthorized access to the SOAP SAPControl endpoint.
5
When was CVE-2017-15297 disclosed?
CVE-2017-15297 was disclosed in July 2017, as part of SAP Security Patch Day.