5.3
CVSSv3

CVE-2023-36926

Published: 08/08/2023 Updated: 15/08/2023
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumented parameter to a particular compatibility value and in turn call read functions. This allows the malicious user to gather some non-sensitive information about the server.  There is no impact on integrity or availability.

Vulnerable Product Search on Vulmon Subscribe to Product

sap host agent 7.22