Host Agent

Vendor:

First CVE: Oct 16, 2017 · Active for 8 years

15
Total CVEs
More Total CVEs than 92% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Host Agent over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 16, 2017
8 years ago
Most Recent CVE
Nov 12, 2024
619 days ago

CVE Severity & Scoring

Host Agent15 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local4 (26.7%)
Network10 (66.7%)
Unknown0 (0.0%)
Physical1 (6.7%)
Adjacent Network0 (0.0%)
Attack Complexity
Low15 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None15 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (26.7%)
High4 (26.7%)
None7 (46.7%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SAP CommonCryptoLib does not perform necessary authentication checks, which may result in missing or wrong authorization checks for an authenticated user, resulting in escalation o
Sep 12, 20239.827NONO
An attacker authenticated as a non-admin user with local access to a server port assigned to the SAP Host Agent (Start Service) - versions 7.21, 7.22, can submit a crafted Configur
Feb 14, 20238.827NONO
SAP Hostcontrol does not require authentication for the SOAP SAPControl endpoint. This is SAP Security Note 2442993.
Oct 16, 20177.526NONO
SAP Host Agent, version 7.21, allows an attacker with admin privileges to use the operation framework to gain root privileges over the underlying operating system, leading to Privi
Apr 14, 20207.224NONO
SAP Host Agent (SAPOSCOL) - version 7.22, allows an unauthenticated attacker with network access to a server port assigned to the SAP Start Service to submit a crafted request whic
Mar 14, 20237.223NONO
In SAP Host Agent (Windows) - versions 7.21, 7.22, an attacker who gains local membership to SAP_LocalAdmin could be able to replace executables with a malicious file that will be
Jan 10, 20236.723NONO
SAP CommonCryptoLib allows an unauthenticated attacker to craft a request, which when submitted to an open port causes a memory corruption error in a library which in turn causes t
Sep 12, 20237.522NONO
An attacker who gains local membership to sapsys group could replace local files usually protected by privileged access. On successful exploitation the attacker could cause high im
Nov 12, 20247.121NONO
In SAP Host Agent (SAPOSCOL) - version 7.22, an attacker may use files created by saposcol to escalate privileges for themselves.
Sep 13, 20224.920NONO
Under certain conditions, the SAP Host Agent logfile shows information which would otherwise be restricted.
May 11, 20225.520NONO

Exploit Exposure

Signals from CVEs in this product scope (15 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (15 CVEs).

Media Mentions

Signals from CVEs in this product scope (15 CVEs).

Top CNAs Publishing CVEs For Host Agent

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.2296.10.4%00
72228.70.7%00
7.2167.41.5%00