Vulnerability Description
The Windows client in SAP Afaria 7.0.6398.0 uses weak permissions (Everyone: read and Everyone: write) for the install folder, which allows local users to gain privileges via a Trojan horse XeService.exe file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sap | Afaria | 7.0.6398.0 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/132681/SAP-Afaria-XeService.exe-7.0.6398.0-
- http://seclists.org/fulldisclosure/2015/Jul/60
- http://www.securityfocus.com/bid/75725
- https://www.portcullis-security.com/security-research-and-downloads/security-adv
- http://packetstormsecurity.com/files/132681/SAP-Afaria-XeService.exe-7.0.6398.0-
- http://seclists.org/fulldisclosure/2015/Jul/60
- http://www.securityfocus.com/bid/75725
- https://www.portcullis-security.com/security-research-and-downloads/security-adv
FAQ
What is CVE-2015-3449?
CVE-2015-3449 is a vulnerability with a CVSS score of 7.2 (HIGH). The Windows client in SAP Afaria 7.0.6398.0 uses weak permissions (Everyone: read and Everyone: write) for the install folder, which allows local users to gain privileges via a Trojan horse XeService....
How severe is CVE-2015-3449?
CVE-2015-3449 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-3449?
Check the references section above for vendor advisories and patch information. Affected products include: Sap Afaria.