First published: Tue Apr 11 2023(Updated: )
Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with deep knowledge of the system to execute scripts on all connected Diagnostics Agents. On successful exploitation, the attacker can completely compromise confidentiality, integrity and availability of the system.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Diagnostics Agent | =720 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-27267.
The title of this vulnerability is 'Due to missing authentication and insufficient input validation the OSCommand Bridge of SAP Diagnostics Agent - version 720'.
The severity of CVE-2023-27267 is critical (8.1).
The SAP Diagnostics Agent version 720 is affected by CVE-2023-27267.
An attacker with deep knowledge of the system can exploit this vulnerability by executing scripts on all connected Diagnostics Agents.