CVE-2023-36926: Information disclosure vulnerability in SAP Host Agent
Published Aug 8, 2023
·Updated
Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumented parameter to a particular compatibility value and in turn call read functions. This allows the attacker to gather some non-sensitive information about the server. There is no impact on integrity or availability.
Affected Software
1 affected component
SAP Host Agent=7.22
Event History
Aug 8, 2023
CVE Published
via MITRE·12:38 AM
Data Sourced
via MITRE·12:38 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-36926.
2
What is the severity of CVE-2023-36926?
The severity of CVE-2023-36926 is medium with a CVSS score of 5.3.
3
What software versions are affected by CVE-2023-36926?
SAP Host Agent version 7.22 is affected by CVE-2023-36926.
4
Is authentication required to exploit CVE-2023-36926?
No, CVE-2023-36926 can be exploited by an unauthenticated attacker.
5
What can an attacker do with CVE-2023-36926?
An attacker can gather non-sensitive information about the server using CVE-2023-36926.