VYPR
Low severity3.7NVD Advisory· Published Aug 8, 2023· Updated Jun 17, 2026

CVE-2023-36926

CVE-2023-36926

Description

Due to missing authentication check in SAP Host Agent - version 7.22, an unauthenticated attacker can set an undocumented parameter to a particular compatibility value and in turn call read functions. This allows the attacker to gather some non-sensitive information about the server.  There is no impact on integrity or availability.

Affected products

3
  • SAP/Host Agent3 versions
    cpe:2.3:a:sap:host_agent:7.22:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:sap:host_agent:7.22:*:*:*:*:*:*:*
    • (no CPE)range: = 7.22
    • (no CPE)range: 7.22

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.