CVE-2023-27498: SAP Host Agent

High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.

SAP Host Agent (SAPOSCOL) - version 7.22, allows an unauthenticated attacker with network access to a server port assigned to the SAP Start Service to submit a crafted request which results in a memory corruption error. This error can be used to reveal but not modify any technical information about the server. It can also make a particular service temporarily unavailable

Affected products

  • SAP Host Agent: version 7.22 only

Published 2023-03-14. Last modified 2026-06-17.