The Simple Diagnostics Agent - versions 1.0 up to version...
Vulnerability Description
The Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any authentication checks for functionalities that can be accessed via localhost on http port 3005. Due to lack of authentication checks, an attacker could access administrative or other privileged functionalities and read, modify, or delete sensitive information and configurations.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-24396
Credits & Attribution
No credits recorded in the NVD database.
References
More from SAP SE
View All →Affected Vendor
SAP SE
View all reports →