CVE-2024-47595
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Nov 12, 2024
Updated: Nov 14, 2024
CWE ID 266
Summary
CVE-2024-47595 is a newly disclosed vulnerability that allows an attacker to gain local membership in the sapsys group. With this access, the attacker can potentially replace local files that are normally protected by privileged access. The impact of this exploit could be significant, as it may result in a loss of confidentiality and integrity within the application. This vulnerability poses a high risk and should be addressed promptly by system administrators to prevent potential data breaches or unauthorized modifications.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Sap Host Agent
Affected Vendors
- SAP SE