First published: Tue Aug 08 2023(Updated: )
Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumented parameter to a particular compatibility value and in turn call read functions. This allows the attacker to gather some non-sensitive information about the server. There is no impact on integrity or availability.
Credit: cna@sap.com cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
Sap Host Agent | =7.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-36926.
The severity of CVE-2023-36926 is medium with a CVSS score of 5.3.
SAP Host Agent version 7.22 is affected by CVE-2023-36926.
No, CVE-2023-36926 can be exploited by an unauthenticated attacker.
An attacker can gather non-sensitive information about the server using CVE-2023-36926.