Advisory
On 08.03.2022 a security relevant correction has been released by SAP SE. The manufacturer resolves an issue within SAP Solution Manager & SAP Focused Run .
SAP Note 3145987 addresses "[CVE-2022-24396] Missing Authentication check in SAP Focused Run (Simple Diagnostics Agent 1.0)" to prevent missing authentication check information disclosure with a hot news risk for exploitation.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance, the team suggests.
Risk specification
SAP Focused Run 'Simple Diagnostic Agent 1.0' does not perform authentication checks for functionalities that can be accessed via localhost HTTP port 3005 rendering a system vulnerable.Solution
SAP Focused Run 'Simple Diagnostic Agent 1.0' now properly enforces authentication and authorization.