CVE-2020-6183 Information
Feb 14, 2021
cve
Description
SAP Host Agent version 7.21 allows an unprivileged user to read the shared memory or write to the shared memory by sending request to the main SAPOSCOL process and receive responses that may contain data read with user root privileges e.g. size of any directory system hardware and OS details leading to Missing Authorization Check vulnerability.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Reference
https://launchpad.support.sap.com//notes/2836445 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=537788812
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
6.5
Share on: