Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with deep knowledge of the system to execute scripts on all connected Diagnostics Agents. On successful exploitation, the attacker can completely compromise confidentiality, integrity and availability of the system.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: sap
Published: 2023-04-11T02:36:15.882Z
Updated: 2024-08-02T12:09:42.300Z
Reserved: 2023-02-27T15:19:34.023Z
Link: CVE-2023-27267
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-04-11T03:15:07.427
Modified: 2024-11-21T07:52:33.933
Link: CVE-2023-27267
Redhat
No data.