CVE-2024-47595: Local Privilege Escalation in SAP Host Agent
An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access. On successful exploitation the attacker could cause high impact on confidentiality and integrity of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-47595?
CVE-2024-47595 has been assessed as a high severity vulnerability due to its potential impact on confidentiality and integrity.
How do I fix CVE-2024-47595?
To remediate CVE-2024-47595, ensure that only authorized users have local membership to the sapsys group and monitor file integrity.
What are the risks associated with exploiting CVE-2024-47595?
Exploiting CVE-2024-47595 may allow an attacker to replace sensitive local files, leading to potential data breaches or application compromise.
Which software versions are affected by CVE-2024-47595?
CVE-2024-47595 specifically affects SAP Host Agent version 7.22.
Who is vulnerable to CVE-2024-47595?
Any organization using SAP Host Agent version 7.22 with improper access controls for the sapsys group is vulnerable to CVE-2024-47595.