Lucene search

K
cve[email protected]CVE-2019-0307
HistoryJun 12, 2019 - 3:29 p.m.

CVE-2019-0307

2019-06-1215:29:00
CWE-311
web.nvd.nist.gov
37
cve-2019-0307
diagnostics agent
solution manager
sap secure storage
credentials
unencrypted
admin privileges

2.7 Low

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:A/AC:L/Au:S/C:P/I:N/A:N

2.4 Low

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

3.9 Low

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.3%

Diagnostics Agent in Solution Manager, version 7.2, stores several credentials such as SLD user connection as well as Solman user communication in the SAP Secure Storage file which is not encrypted by default. By decoding these credentials, an attacker with admin privileges could gain access to the entire configuration, but no system sensitive information can be gained.

Affected configurations

NVD
Node
sapsolution_managerMatch7.2

CNA Affected

[
  {
    "product": "SAP Solution Manager(Diagnostics Agent)",
    "vendor": "SAP SE",
    "versions": [
      {
        "status": "affected",
        "version": "< 7.2"
      }
    ]
  }
]

2.7 Low

CVSS2

Attack Vector

ADJACENT_NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:A/AC:L/Au:S/C:P/I:N/A:N

2.4 Low

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

3.9 Low

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

71.3%

Related for CVE-2019-0307