CVE-2023-24523: High severity sap host agent vulnerability
An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent (Start Service) - versions 7.21, 7.22, can submit a crafted ConfigureOutsideDiscovery request with an operating system command which will be executed with administrator privileges. The OS command can read or modify any user or system data and can make the system unavailable.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-24523?
CVE-2023-24523 is a vulnerability that allows an authenticated non-admin user with local access to a server port assigned to the SAP Host Agent (Start Service) to execute arbitrary commands with administrator privileges.
Which versions of SAP Host Agent are affected by CVE-2023-24523?
Versions 7.21 and 7.22 of SAP Host Agent are affected by CVE-2023-24523.
What is the severity of CVE-2023-24523?
CVE-2023-24523 has a severity rating of 8.8 (high).
How can an attacker exploit CVE-2023-24523?
An attacker can exploit CVE-2023-24523 by submitting a crafted ConfigureOutsideDiscovery request with an operating system command, which will be executed with administrator privileges.
Are there any references for CVE-2023-24523?
Yes, you can refer to the following sources for more information about CVE-2023-24523: [SAP Note 3285757](https://launchpad.support.sap.com/#/notes/3285757) and [SAP Security Note](https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html).