CVE-2022-35295: Medium severity SAP Host Agent vulnerability
In SAP Host Agent (SAPOSCOL) - version 7.22, an attacker may use files created by saposcol to escalate privileges for themselves.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this SAP Host Agent vulnerability?
The vulnerability ID for this SAP Host Agent vulnerability is CVE-2022-35295.
What is the severity of CVE-2022-35295?
The severity of CVE-2022-35295 is medium with a CVSS score of 4.9.
What is the affected software for CVE-2022-35295?
The affected software for CVE-2022-35295 is SAP Host Agent version 7.22.
How can an attacker exploit CVE-2022-35295?
An attacker can exploit CVE-2022-35295 by using files created by saposcol to escalate privileges for themselves.
Are there any references for CVE-2022-35295?
Yes, you can find references for CVE-2022-35295 at the following links: [Packet Storm Security](http://packetstormsecurity.com/files/170233/SAP-Host-Agent-Privilege-Escalation.html), [SecLists](http://seclists.org/fulldisclosure/2022/Dec/12), [SAP Note](https://launchpad.support.sap.com/#/notes/3159736).