Skip links
Picture of Vahagn Vardanian

Vahagn Vardanian

Co-founder and CTO of RedRays

CVE-2020-6234 Privilege Escalation in SAP Host Agent, SAP security note 2902645

SAP Note 2902645

SAP security note 2902645, “[CVE-2020-6234] Privilege Escalation in SAP Host Agent”. Below are the symptom, SAP recommended solution and references.

Description

Symptom

An attacker with Host Agent admin privileges may use the SAP Host Agent’s Operation Framework to gain root privileges over the underlying operating system.

Solution

Please upgrade SAP Host Agent to at least version 7.21 PL46. We always recommend upgrading to the latest available version.

Follow the procedure described in Note 1031096.

Reason and prerequisites

  • SAP Host Agent PL45 or lower is used
  • Attacker must have access to non-root user credentials like <SID>adm, e.g., daaadm
  • <SID>adm must be configured as service/admin_user in SAP Host Agent’s profile

CVSS

Score 7.2 Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

References

Full note on SAP: SAP Support Launchpad note 2902645

Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].

Explore More