Loading HuntDB...

GHSA-xxh6-f3x3-2xgf

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent (Start Service) - versions 7.21, 7.22, can submit a crafted ConfigureOutsideDiscovery request with an operating system command which will be executed with administrator privileges. The OS command can read or modify any user or system data and can make the system unavailable.

Related CVEs

Key Information

GHSA ID
GHSA-xxh6-f3x3-2xgf
Published
February 14, 2023 6:31 AM
Last Modified
February 21, 2023 9:30 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 18, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.