Advisory
SAP takes the security of its vast product portfolio very seriously and thus releases security fixes for
vulnerabilities reported by external researchers and their customers every second Tuesday of the month.
SAP Note 2902645
was released on
14.04.2020 and deals with
"[CVE-2020-6234] Privilege Escalation in SAP Host Agent" within SAP Host Agent.
We advice you to follow the instructions, to resolve
command injection
with a
high potential for exploitation
in component BC-CCM-HAG.
According to SAP Security Advisory team a workaround does not exist. It is advisable to implement the correction as monthly patch process.
Risk specification
An authenticated attacker might gain root privileges on the underlying oprtating system.Solution
The privilege escalation is no longer possible
- 9.9 [CVE-2021-38163] Unrestricted File Upload vulnerability in SAP NetWeaver (Visual Composer 7.0 RT)
- 7.2 [CVE-2020-6191] Missing Input Validation in SAP Landscape Management
- 7.2 [CVE-2020-6192] Missing Input Validation in SAP Landscape Management
- 7.2 [CVE-2020-6236] Privilege Escalation in SAP Landscape Management (SAP Adaptive Extensions)
- 6.5 [CVE-2021-38180] CSV Injection in SAP Business One