6.5

CVE-2022-31589

Due to improper authorization check, business users who are using Israeli File from SHAAM program (/ATL/VQ23 transaction), are granted more than needed authorization to perform certain transaction, which may lead to users getting access to data that would otherwise be restricted.

Data is provided by the National Vulnerability Database (NVD)
SAPErp Financial Accounting Version618
SAPErp Financial Accounting Version720
SAPErp Localization For Cee Countries Versionc-cee_110_600
SAPErp Localization For Cee Countries Versionc-cee_110_602
SAPErp Localization For Cee Countries Versionc-cee_110_603
SAPErp Localization For Cee Countries Versionc-cee_110_604
SAPErp Localization For Cee Countries Versionc-cee_110_700
SAPS/4hana Version100
SAPS/4hana Version101
SAPS/4hana Version102
SAPS/4hana Version103
SAPS/4hana Version104
SAPS/4hana Version105
SAPS/4hana Version106
SAPS/4hana Version107
SAPS/4hana Version108
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.19% 0.408
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:P/I:N/A:N
CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.