Back to search
CVE-2022-24396
Published: Mar 8, 2022
Modified: Aug 3, 2024
PUBLISHED
Description
The Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any authentication checks for functionalities that can be accessed via localhost on http port 3005. Due to lack of authentication checks, an attacker could access administrative or other privileged functionalities and read, modify, or delete sensitive information and configurations.
| Vendor | Product | Versions |
|---|---|---|
SAP SE | SAP Focused Run (Simple Diagnostics Agent) | affected < >= 1.0affected < 1.58 |
Weaknesses (CWE)
References
https://dam.sap.com/mac/embed/public/pdf/a/ucQrx6G.htm?rc=10
x_refsource_MISC
https://launchpad.support.sap.com/#/notes/3145987
x_refsource_MISC
20220621 # Onapsis Security Advisory 2022-0004: Missing Authentication check in SAP Focused Run (Simple Diagnostics Agent 1.0)
mailing-list
x_refsource_FULLDISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now