First published: Tue Sep 13 2022(Updated: )
In SAP Host Agent (SAPOSCOL) - version 7.22, an attacker may use files created by saposcol to escalate privileges for themselves.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Host Agent | =7.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this SAP Host Agent vulnerability is CVE-2022-35295.
The severity of CVE-2022-35295 is medium with a CVSS score of 4.9.
The affected software for CVE-2022-35295 is SAP Host Agent version 7.22.
An attacker can exploit CVE-2022-35295 by using files created by saposcol to escalate privileges for themselves.
Yes, you can find references for CVE-2022-35295 at the following links: [Packet Storm Security](http://packetstormsecurity.com/files/170233/SAP-Host-Agent-Privilege-Escalation.html), [SecLists](http://seclists.org/fulldisclosure/2022/Dec/12), [SAP Note](https://launchpad.support.sap.com/#/notes/3159736).