First published: Tue Nov 12 2024(Updated: )
An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access. On successful exploitation the attacker could cause high impact on confidentiality and integrity of the application.
Credit: cna@sap.com
Affected Software | Affected Version | How to fix |
---|---|---|
SAP Host Agent | =7.22 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-47595 has been assessed as a high severity vulnerability due to its potential impact on confidentiality and integrity.
To remediate CVE-2024-47595, ensure that only authorized users have local membership to the sapsys group and monitor file integrity.
Exploiting CVE-2024-47595 may allow an attacker to replace sensitive local files, leading to potential data breaches or application compromise.
CVE-2024-47595 specifically affects SAP Host Agent version 7.22.
Any organization using SAP Host Agent version 7.22 with improper access controls for the sapsys group is vulnerable to CVE-2024-47595.