CVE-2015-3449
16.07.2015, 14:59
The Windows client in SAP Afaria 7.0.6398.0 uses weak permissions (Everyone: read and Everyone: write) for the install folder, which allows local users to gain privileges via a Trojan horse XeService.exe file.Enginsight
Vendor | Product | Version |
---|---|---|
sap | afaria | 7.0.6398.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References