SAP Landscape Management, version 3.0, and SAP Adaptive Extensions, version 1.0, allows an attacker with admin_group privileges to change ownership and permissions (including S-user ID bit s-bit) of arbitrary files remotely. This results in the possibility to execute these files as root user from a non-root context, leading to Privilege Escalation.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-27386 SAP Landscape Management, version 3.0, and SAP Adaptive Extensions, version 1.0, allows an attacker with admin_group privileges to change ownership and permissions (including S-user ID bit s-bit) of arbitrary files remotely. This results in the possibility to execute these files as root user from a non-root context, leading to Privilege Escalation.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: sap

Published:

Updated: 2024-08-04T08:55:22.273Z

Reserved: 2020-01-08T00:00:00

Link: CVE-2020-6236

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-04-14T19:15:18.280

Modified: 2024-11-21T05:35:21.340

Link: CVE-2020-6236

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses