Описание
SAP SAPCAR allows local users to change the permissions of arbitrary files and consequently gain privileges via a hard link attack on files extracted from an archive, possibly related to SAP Security Note 2327384.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party Advisory
- Third Party AdvisoryVDB Entry
- ExploitThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party Advisory
- Third Party AdvisoryVDB Entry
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:sap:sapcar_archive_tool:-:*:*:*:*:*:*:*
EPSS
Процентиль: 44%
0.0022
Низкий
5.8 Medium
CVSS3
4.4 Medium
CVSS2
Дефекты
CWE-264
Связанные уязвимости
CVSS3: 5.8
github
больше 3 лет назад
SAP SAPCAR allows local users to change the permissions of arbitrary files and consequently gain privileges via a hard link attack on files extracted from an archive, possibly related to SAP Security Note 2327384.
EPSS
Процентиль: 44%
0.0022
Низкий
5.8 Medium
CVSS3
4.4 Medium
CVSS2
Дефекты
CWE-264