Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-6183

Опубликовано: 12 фев. 2020
Источник: nvd
CVSS3: 5.3
CVSS3: 6.5
CVSS2: 6.4
EPSS Низкий

Описание

SAP Host Agent, version 7.21, allows an unprivileged user to read the shared memory or write to the shared memory by sending request to the main SAPOSCOL process and receive responses that may contain data read with user root privileges e.g. size of any directory, system hardware and OS details, leading to Missing Authorization Check vulnerability.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:sap:host_agent:7.21:*:*:*:*:*:*:*

EPSS

Процентиль: 48%
0.00249
Низкий

5.3 Medium

CVSS3

6.5 Medium

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-862

Связанные уязвимости

github
больше 3 лет назад

SAP Host Agent, version 7.21, allows an unprivileged user to read the shared memory or write to the shared memory by sending request to the main SAPOSCOL process and receive responses that may contain data read with user root privileges e.g. size of any directory, system hardware and OS details, leading to Missing Authorization Check vulnerability.

EPSS

Процентиль: 48%
0.00249
Низкий

5.3 Medium

CVSS3

6.5 Medium

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-862