Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with deep knowledge of the system to execute scripts on all connected Diagnostics Agents. On successful exploitation, the attacker can completely compromise confidentiality, integrity and availability of the system.
Metrics
Affected Vendors & Products
References
History
Fri, 07 Feb 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: sap
Published:
Updated: 2025-02-07T19:32:45.187Z
Reserved: 2023-02-27T15:19:34.023Z
Link: CVE-2023-27267

Updated: 2024-08-02T12:09:42.300Z

Status : Modified
Published: 2023-04-11T03:15:07.427
Modified: 2024-11-21T07:52:33.933
Link: CVE-2023-27267

No data.