SAP PowerDesigner Proxy - version 16.7, allows an...
High severity
Unreviewed
Published
Jun 15, 2022
to the GitHub Advisory Database
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Jun 14, 2022
Published to the GitHub Advisory Database
Jun 15, 2022
Last updated
Jan 27, 2023
SAP PowerDesigner Proxy - version 16.7, allows an attacker with low privileges and has local access, with the ability to work around system’s root disk access restrictions to Write/Create a program file on system disk root path, which could then be executed with elevated privileges of the application during application start up or reboot, potentially compromising Confidentiality, Integrity and Availability of the system.
References