Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - version 720, allows an attacker to execute malicious scripts on all connected Diagnostics Agents running on Windows. On successful exploitation, the attacker can completely compromise confidentiality, integrity and availability of the system.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: sap
Published: 2023-04-11T02:37:07.584Z
Updated: 2024-08-02T12:16:35.432Z
Reserved: 2023-03-02T03:37:32.233Z
Link: CVE-2023-27497
Vulnrichment
No data.
NVD
Status : Modified
Published: 2023-04-11T03:15:07.487
Modified: 2024-11-21T07:53:01.633
Link: CVE-2023-27497
Redhat
No data.