First published: Mon Oct 16 2017(Updated: )
SAP Hostcontrol does not require authentication for the SOAP SAPControl endpoint. This is SAP Security Note 2442993.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Host Agent | =7.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15297 has a critical severity due to the lack of authentication for the SOAP SAPControl endpoint.
To fix CVE-2017-15297, ensure that authentication is required for the SOAP SAPControl endpoint as described in SAP Security Note 2442993.
CVE-2017-15297 affects the SAP Host Agent version 7.21.
CVE-2017-15297 is an authentication vulnerability that allows unauthorized access to the SOAP SAPControl endpoint.
CVE-2017-15297 was disclosed in July 2017, as part of SAP Security Patch Day.