Description
SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to work around system’s root disk access restrictions to Write/Create a program file on system disk root path, which could then be executed with elevated privileges of the application during application start up or reboot, potentially compromising Confidentiality, Integrity and Availability of the system.
References
https://launchpad.support.sap.com/#/notes/3197005
Permissions RequiredVendor Advisory
https://launchpad.support.sap.com/#/notes/3197005
Permissions RequiredVendor Advisory
CVSS impact metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
7.8 · High
Information
Source identifier
Vulnerability status
Modified
Published
2022-06-14T17:15:07.680Z
3 years agoLast modified
2024-11-21T06:04:48.103Z
1 year ago