SAP Host Agent 7.22 SAPOSCOL Remote Mem Corruption (Unauthenticated)
CVE-2023-27498 Published on March 14, 2023
Memory Corruption vulnerability in SAP Host Agent (SAPOSCOL)
SAP Host Agent (SAPOSCOL) - version 7.22, allows an unauthenticated attacker with network access to a server port assigned to the SAP Start Service to submit a crafted request which results in a memory corruption error. This error can be used to reveal but not modify any technical information about the server. It can also make a particular service temporarily unavailable
Vulnerability Analysis
CVE-2023-27498 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a small impact on confidentiality, a small impact on integrity, and a small impact on availability.
Weakness Type
What is a Stack Overflow Vulnerability?
A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
CVE-2023-27498 has been classified to as a Stack Overflow vulnerability or weakness.
Products Associated with CVE-2023-27498
Want to know whenever a new CVE is published for SAP Host Agent? stack.watch will email you.
Affected Versions
Host Agent (SAPOSCOL) Version 7.22 is affected by CVE-2023-27498Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.