The Simple Diagnostics Agent 1.0 (up to version 1.57.*) does not perform any authentication checks for functionalities that can be accessed via localhost on http port 3005. Due to lack of authentication checks, an attacker could accsess administrative or other privileged functionalities and read, modify or delete sensitive information and configurations.
SAP Focused Run 1.0, SAP Focused Run 2.0, SAP Focused Run 3.0, SDA < SP 58, SHA < 7.22 PL55
Missing authentication, SDA port 3005, local access, lack of priviledges , KBA , SV-FRN-INF-SDA , Simple Diagnostic Agent (SDA) , Problem
About this pageThis is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).
Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.