CVE-2024-39593 – [CVE-2024-39593] Information Disclosure vulnerability in SAP Landscape Management
https://notcve.org/view.php?id=CVE-2024-39593
SAP Landscape Management allows an authenticated user to read confidential data disclosed by the REST Provider Definition response. Successful exploitation can cause high impact on confidentiality of the managed entities. SAP Landscape Management permite a un usuario autenticado leer datos confidenciales revelados por la respuesta de Provider Definition REST. La explotación exitosa puede causar un gran impacto en la confidencialidad de las entidades gestionadas. • https://me.sap.com/notes/3466801 https://url.sap/sapsecuritypatchday • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •
CVE-2023-26458 – Information Disclosure vulnerability in SAP Landscape Management
https://notcve.org/view.php?id=CVE-2023-26458
An information disclosure vulnerability exists in SAP Landscape Management - version 3.0, enterprise edition. It allows an authenticated SAP Landscape Management user to obtain privileged access to other systems making those other systems vulnerable to information disclosure and modification.The disclosed information is for Diagnostics Agent Connection via Java SCS Message Server of an SAP Solution Manager system and can only be accessed by authenticated SAP Landscape Management users, but they can escalate their privileges to the SAP Solution Manager system. • https://launchpad.support.sap.com/#/notes/3312733 https://www.sap.com/documents/2022/02/fa865ea4-167e-0010-bca6-c68f7e60039b.html • CWE-668: Exposure of Resource to Wrong Sphere •
CVE-2020-6236
https://notcve.org/view.php?id=CVE-2020-6236
SAP Landscape Management, version 3.0, and SAP Adaptive Extensions, version 1.0, allows an attacker with admin_group privileges to change ownership and permissions (including S-user ID bit s-bit) of arbitrary files remotely. This results in the possibility to execute these files as root user from a non-root context, leading to Privilege Escalation. SAP Landscape Management, versión 3.0, y SAP Adaptive Extensions, versión 1.0, permite a un atacante con privilegios admin_group cambiar la propiedad y los permisos (incluyendo el bit S-bit del ID S-user) de archivos arbitrarios remotamente. Esto resulta en la posibilidad de ejecutar estos archivos como usuario root desde un contexto no root, conllevando a una Escalada de Privilegios. • https://launchpad.support.sap.com/#/notes/2902456 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=544214202 • CWE-269: Improper Privilege Management •
CVE-2020-6191
https://notcve.org/view.php?id=CVE-2020-6191
SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious executables with root privileges in SAP Host Agent via SAP Landscape Management due to Missing Input Validation. SAP Landscape Management, versión 3.0, permite a un atacante con privilegios de administrador ejecutar archivos ejecutables maliciosos con privilegios root en SAP Host Agent por medio de SAP Landscape Management, debido a una Falta de Comprobación de Entrada. • https://launchpad.support.sap.com/#/notes/2878030 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=537788812 • CWE-20: Improper Input Validation •
CVE-2020-6192
https://notcve.org/view.php?id=CVE-2020-6192
SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root privileges in SAP Host Agent via SAP Landscape Management. SAP Landscape Management, versión 3.0, permite a un atacante con privilegios de administrador ejecutar comandos maliciosos con privilegios root en SAP Host Agent, por medio de SAP Landscape Management. • https://launchpad.support.sap.com/#/notes/2877968 https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=537788812 • CWE-20: Improper Input Validation •