CVE-2023-27497: Multiple vulnerabilities in SAP Diagnostics Agent (EventLogServiceCollector)
Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - version 720, allows an attacker to execute malicious scripts on all connected Diagnostics Agents running on Windows. On successful exploitation, the attacker can completely compromise confidentiality, integrity and availability of the system.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this exploit?
The vulnerability ID of this exploit is CVE-2023-27497.
What is the severity of CVE-2023-27497?
The severity of CVE-2023-27497 is critical with a severity value of 9.8.
Which software is affected by CVE-2023-27497?
SAP Diagnostics Agent version 720 is affected by CVE-2023-27497.
How can an attacker exploit CVE-2023-27497?
An attacker can exploit CVE-2023-27497 by executing malicious scripts on all connected Diagnostics Agents running on Windows.
Are all versions of Microsoft Windows vulnerable to CVE-2023-27497?
No, all versions of Microsoft Windows are not vulnerable to CVE-2023-27497.