VYPR
Unrated severityNVD Advisory· Published Jul 16, 2015· Updated May 6, 2026

CVE-2015-3449

CVE-2015-3449

Description

The Windows client in SAP Afaria 7.0.6398.0 uses weak permissions (Everyone: read and Everyone: write) for the install folder, which allows local users to gain privileges via a Trojan horse XeService.exe file.

Affected products

1
  • cpe:2.3:a:sap:afaria:7.0.6398.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.