CVE-2022-24396 Information
Jun 07, 2022
cve
Description
The Simple Diagnostics Agent - versions 1.0 up to version 1.57 does not perform any authentication checks for functionalities that can be accessed via localhost on http port 3005. Due to lack of authentication checks an attacker could access administrative or other privileged functionalities and read modify or delete sensitive information and configurations.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
https://dam.sap.com/mac/embed/public/pdf/a/ucQrx6G.htm?rc=10 https://launchpad.support.sap.com/#/notes/3145987
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
7.8
Share on: