8.1

CVE-2022-22530

The F0743 Create Single Payment application of SAP S/4HANA - versions 100, 101, 102, 103, 104, 105, 106, does not check uploaded or downloaded files. This allows an attacker with basic user rights to inject dangerous content or malicious code which could result in critical information being modified or completely compromise the availability of the application.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SAPS/4hana Version100
SAPS/4hana Version101
SAPS/4hana Version102
SAPS/4hana Version103
SAPS/4hana Version104
SAPS/4hana Version105
SAPS/4hana Version106
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.49% 0.626
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.1 2.8 5.2
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
nvd@nist.gov 7.5 8 7.8
AV:N/AC:L/Au:S/C:N/I:P/A:C