Advisory
A note with CVSS 6.3 for component BC-CCM-HAG was released by SAP on 12.11.2024. The correction/advisory 3509619 was described with "[CVE-2024-47595] Local Privilege Escalation in SAP Host Agent" and affects the system type SAP Host Agent.
A workaround does not exist, according to SAP Security Advisory team. It is advisable to implement the correction as part of maintenance.
The vulnerability addressed is insecure file operations within SAP Host Agent.
Risk specification
SAP Host Agent allows an authenticated attacker to replace local files which are usually protected by privileged access, resulting in high impact on confidentiality and integrity of the application.Solution
The Host Agent no longer allows unauthorized access to files protected by privileged access.