SAP security note 2902645, “[CVE-2020-6234] Privilege Escalation in SAP Host Agent”. Below are the symptom, SAP recommended solution and references.
Description
Symptom
An attacker with Host Agent admin privileges may use the SAP Host Agent’s Operation Framework to gain root privileges over the underlying operating system.
Solution
Please upgrade SAP Host Agent to at least version 7.21 PL46. We always recommend upgrading to the latest available version.
Follow the procedure described in Note 1031096.
Reason and prerequisites
- SAP Host Agent PL45 or lower is used
- Attacker must have access to non-root user credentials like <SID>adm, e.g., daaadm
- <SID>adm must be configured as service/admin_user in SAP Host Agent’s profile
CVSS
Score 7.2 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
References
Full note on SAP: SAP Support Launchpad note 2902645
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
