Home
Description
A security audit identified a privilege escalation vulnerability in Operations Agent(<=OA 12.29) on Windows. Under specific conditions Operations Agent may run executables from specific writeable locations.Thanks to Manuel Rickli & Philippe Leiser of Oneconsult AG for reporting this vulnerability
Problem types
CWE-280 Improper handling of insufficient permissions or privileges
Product status
OA 12.22 (custom)
References
portal.microfocus.com/s/article/KM000046068
