First published: Tue Apr 11 2023(Updated: )
Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - version 720, allows an attacker to execute malicious scripts on all connected Diagnostics Agents running on Windows. On successful exploitation, the attacker can completely compromise confidentiality, integrity and availability of the system.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Diagnostics Agent | =720 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this exploit is CVE-2023-27497.
The severity of CVE-2023-27497 is critical with a severity value of 9.8.
SAP Diagnostics Agent version 720 is affected by CVE-2023-27497.
An attacker can exploit CVE-2023-27497 by executing malicious scripts on all connected Diagnostics Agents running on Windows.
No, all versions of Microsoft Windows are not vulnerable to CVE-2023-27497.