SAP SE / Host Agent
15 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-47595 | Local Privilege Escalation in SAP Host Agent | HIGH | 7.1 | Nov 12, 2024 |
| CVE-2023-40309 | Missing Authorization check in SAP CommonCryptoLib | CRITICAL | 9.8 | Sep 12, 2023 |
| CVE-2023-40308 | Memory Corruption vulnerability in SAP CommonCryptoLib | HIGH | 7.5 | Sep 12, 2023 |
| CVE-2023-36926 | Information disclosure vulnerability in SAP Host Agent | MEDIUM | 5.3 | Aug 8, 2023 |
| CVE-2023-27498 | Memory Corruption vulnerability in SAP Host Agent (SAPOSCOL) | HIGH | 7.2 | Mar 14, 2023 |
| CVE-2023-24523 | An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent (Start Service) - versions 7.21, 7.22, can subm… | HIGH | 8.8 | Feb 14, 2023 |
| CVE-2023-0012 | Local Privilege Escalation in SAP Host Agent (Windows) | MEDIUM | 6.7 | Jan 10, 2023 |
| CVE-2022-35295 | In SAP Host Agent (SAPOSCOL) - version 7.22, an attacker may use files created by saposcol to escalate privileges for themselves. | MEDIUM | 4.9 | Sep 13, 2022 |
| CVE-2022-29614 | SAP startservice - of SAP NetWeaver Application Server ABAP, Application Server Java, ABAP Platform and HANA Database - versions KERNEL 7.22, 7.49, 7.53, 7.77,… | MEDIUM | 5.0 | Jun 14, 2022 |
| CVE-2022-29612 | SAP NetWeaver, ABAP Platform and SAP Host Agent - versions KERNEL 7.22, 7.49, 7.53, 7.77, 7.81, 7.85, 7.86, 7.87, 7.88, 8.04, KRNL64NUC 7.22, 7.22EXT, 7.49, KR… | MEDIUM | 4.3 | Jun 14, 2022 |
| CVE-2022-28774 | Under certain conditions, the SAP Host Agent logfile shows information which would otherwise be restricted. | MEDIUM | 5.5 | May 11, 2022 |
| CVE-2020-6234 | SAP Host Agent, version 7.21, allows an attacker with admin privileges to use the operation framework to gain root privileges over the underlying operating sys… | HIGH | 7.2 | Apr 14, 2020 |
| CVE-2020-6186 | SAP Host Agent, version 7.21, allows an attacker to cause a slowdown in processing of username/password-based authentication requests of the SAP Host Agent, le… | HIGH | 7.5 | Feb 12, 2020 |
| CVE-2020-6183 | SAP Host Agent, version 7.21, allows an unprivileged user to read the shared memory or write to the shared memory by sending request to the main SAPOSCOL proce… | MEDIUM | 6.5 | Feb 12, 2020 |
| CVE-2017-15297 | SAP Hostcontrol does not require authentication for the SOAP SAPControl endpoint. This is SAP Security Note 2442993. | HIGH | 7.5 | Oct 16, 2017 |
Showing 1 to 15 of 15 CVEs