CVE-2015-3449: SAP Afaria

High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.

The Windows client in SAP Afaria 7.0.6398.0 uses weak permissions (Everyone: read and Everyone: write) for the install folder, which allows local users to gain privileges via a Trojan horse XeService.exe file.

Affected products

  • SAP Afaria: version 7.0.6398.0 only

Published 2015-07-16. Last modified 2026-06-17.