Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fm4v-rfjh-p9cc

Опубликовано: 11 фев. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

Solution Manager (Diagnostics Root Cause Analysis Tools) - version 720, allows an administrator to execute code on all connected Diagnostics Agents and browse files on their systems. An attacker could thereby control the managed systems. It is considered that this is a missing segregation of duty for the SAP Solution Manager administrator. Impacts of unauthorized execution of commands can lead to sensitive information disclosure, loss of system integrity and denial of service.

Solution Manager (Diagnostics Root Cause Analysis Tools) - version 720, allows an administrator to execute code on all connected Diagnostics Agents and browse files on their systems. An attacker could thereby control the managed systems. It is considered that this is a missing segregation of duty for the SAP Solution Manager administrator. Impacts of unauthorized execution of commands can lead to sensitive information disclosure, loss of system integrity and denial of service.

EPSS

Процентиль: 62%
0.0043
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
nvd
почти 4 года назад

Solution Manager (Diagnostics Root Cause Analysis Tools) - version 720, allows an administrator to execute code on all connected Diagnostics Agents and browse files on their systems. An attacker could thereby control the managed systems. It is considered that this is a missing segregation of duty for the SAP Solution Manager administrator. Impacts of unauthorized execution of commands can lead to sensitive information disclosure, loss of system integrity and denial of service.

CVSS3: 9.1
fstec
почти 4 года назад

Уязвимость инструмента Solution Manager Diagnostics (Root Cause Analysis) платформы управления программными средами SAP Solution Manager, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 62%
0.0043
Низкий

9.1 Critical

CVSS3