6.5
CVE-2022-22535
- EPSS 0.23%
- Published 09.02.2022 23:15:18
- Last modified 21.11.2024 06:46:58
- Source cna@sap.com
- Teams watchlist Login
- Open Login
SAP ERP HCM Portugal - versions 600, 604, 608, does not perform necessary authorization checks for a report that reads the payroll data of employees in a certain area. Since the affected report only reads the payroll information, the attacker can neither modify any information nor cause availability impacts.
Data is provided by the National Vulnerability Database (NVD)
SAP ≫ Erp Human Capital Management Version600 SwEditionportugal
SAP ≫ Erp Human Capital Management Version604 SwEditionportugal
SAP ≫ Erp Human Capital Management Version608 SwEditionportugal
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.23% | 0.43 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 4 | 8 | 2.9 |
AV:N/AC:L/Au:S/C:P/I:N/A:N
|
CWE-862 Missing Authorization
The product does not perform an authorization check when an actor attempts to access a resource or perform an action.