CVE-2022-35295Improper Handling of Exceptional Conditions in SE SAP Host Agent

Severity
4.9MEDIUMNVD
EPSS
1.2%
top 20.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 13
Latest updateSep 14

Description

In SAP Host Agent (SAPOSCOL) - version 7.22, an attacker may use files created by saposcol to escalate privileges for themselves.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 1.2 | Impact: 3.6

Affected Packages2 packages

NVDsap/host_agent7.22
CVEListV5sap_se/sap_host_agent7.22

🔴Vulnerability Details

2
GHSA
GHSA-q5fc-mgmp-vrq5: Under certain conditions, the application SAP BusinessObjects Business Intelligence Platform (Version Management System) - versions 420, 430, exposes2022-09-14
CVEList
CVE-2022-35295: In SAP Host Agent (SAPOSCOL) - version 72022-09-13
CVE-2022-35295 — SAP SE SAP Host Agent vulnerability | cvebase