VendorsSAPhost_agent7.22
Vulnerabilities

SAP Host Agent 7.22

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2023-24523
An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent (Start Service) - versions 7.21, 7.22, can submit a crafted ConfigureOutsideDiscovery request with an operating system command which will be executed with administrator privileges.  The OS command can read or modify any user or system data and can make the system unavailable.
Published 2023-02-14 · Modified
8.8EPSS 0.002
CVE-2023-27498
Memory Corruption vulnerability in SAP Host Agent (SAPOSCOL)
Published 2023-03-14 · Modified
7.2EPSS 0.005
CVE-2024-47595
Local Privilege Escalation in SAP Host Agent
Published 2024-11-12 · Analyzed
7.1EPSS 0.001
CVE-2023-0012
Local Privilege Escalation in SAP Host Agent (Windows)
Published 2023-01-10 · Modified
6.7EPSS 0.002
CVE-2022-28774
Under certain conditions, the SAP Host Agent logfile shows information which would otherwise be restricted.
Published 2022-05-11 · Modified
5.5EPSS 0.002
CVE-2023-36926
Information disclosure vulnerability in SAP Host Agent
Published 2023-08-08 · Modified
5.3EPSS 0.005
CVE-2022-29614
SAP startservice - of SAP NetWeaver Application Server ABAP, Application Server Java, ABAP Platform and HANA Database - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, SAPHOSTAGENT 7.22, - on Unix systems, s-bit helper program sapuxuserchk, can be abused physically resulting in a privilege escalation of an attacker leading to low impact on confidentiality and integrity, but a profound impact on availability.
Published 2022-06-14 · Modified
5.0EPSS 0.004
CVE-2022-35295
In SAP Host Agent (SAPOSCOL) - version 7.22, an attacker may use files created by saposcol to escalate privileges for themselves.
Published 2022-09-13 · Modified
4.9EPSS 0.017
CVE-2022-29612
SAP NetWeaver, ABAP Platform and SAP Host Agent - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, 8.04, KRNL64NUC 7.22, 7.22EXT, 7.49, KRNL64UC 7.22, 7.22EXT, 7.49, 7.53, 8.04, SAPHOSTAGENT 7.22, allows an authenticated user to misuse a function of sapcontrol webfunctionality(startservice) in Kernel which enables malicious users to retrieve information. On successful exploitation, an attacker can obtain technical information like system number or physical address, which is otherwise restricted, causing a limited impact on the confidentiality of the application.
Published 2022-06-14 · Modified
4.3EPSS 0.007