CVE-2022-24396 Information

Description

The Simple Diagnostics Agent - versions 1.0 up to version 1.57 does not perform any authentication checks for functionalities that can be accessed via localhost on http port 3005. Due to lack of authentication checks an attacker could access administrative or other privileged functionalities and read modify or delete sensitive information and configurations.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Reference

https://dam.sap.com/mac/embed/public/pdf/a/ucQrx6G.htm?rc=10 https://launchpad.support.sap.com/#/notes/3145987

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

7.8

Share on: