Advisory
A note with CVSS 3.7 for component BC-CCM-HAG was released by SAP on 08.08.2023. The correction/advisory 3358328 was described with "[CVE-2023-36926] Information disclosure vulnerability in SAP Host Agent" and affects the system type SAP Host Agent.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is missing authentication check / improper authentication check within SAP Host Agent.
Risk specification
SAP Host Agent allows an unauthenticated attacker to change a parameter to a compatibility value, enabling the attacker to read data and resulting in an information disclosure vulnerability.Solution
An additional authentication check is now done in SAP Host Agent